Privilege escalation via writable configuration files in Progress Flowmon
Vulnerability Description
A vulnerability exists in Progress Flowmon versions prior 12.5.6 where certain system configuration files have incorrect file permissions, allowing a user with access to the default flowmon system user account used for SSH access to potentially escalate privileges to root during service initialization.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11906
Credits & Attribution
No credits recorded in the NVD database.
More from Progress Software
View All →Affected Vendor
Progress Software
View all reports →