CVE-2025-62577 - CVE House
Back to Database
Status published High CVE-2025-62577

ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect...

Vulnerability Description

ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged user with access to the management server may obtain database credentials, potentially allowing execution of OS commands with administrator privileges.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62577

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Fsas Technologies Inc.

View all reports →

Affected Software

ETERNUS SF AdvancedCopy Manager Standard Edition (for Solaris 10/ 11), ETERNUS SF Storage Cruiser (for Solaris 10/ 11), ETERNUS SF AdvancedCopy Manager Standard Edition (for RHEL 7/ 8/ 9), ETERNUS SF Expressn (for RHEL 7/ 8/ 9), ETERNUS SF Storage Cruisern (for RHEL 7/ 8/ 9), ETERNUS SF AdvancedCopy Manager Standard Edition (for Windows Server 2016/ 2019/ 2022), ETERNUS SF Express (for Windows Server 2016/ 2019/ 2022), ETERNUS SF Storage Cruiser (for Windows Server 2016/ 2019/ 2022)
Vulnerable Versions:
15.0/ 15.1/ 15.2/ 15.3/ 16.0/ 16.1/ 16.2/ 16.3/ 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1, 16.2/ 16.3/ 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1, 16.4/ 16.5/ 16.6/ 16.7/ 16.8/ 16.9/ 16.9.1

Timeline

Official Publish: October 20th, 2025
Last Modified: November 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)