CVE-2025-42959

An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target system is fully patched, successful exploitation could result in complete system compromise, affecting confidentiality, integrity, and availability.
Configurations

No configuration.

History

No history.

Information

Published : 2025-07-08 01:15

Updated : 2025-07-08 16:18


NVD link : CVE-2025-42959

Mitre link : CVE-2025-42959

CVE.ORG link : CVE-2025-42959


JSON object : View

Products Affected

No product.

CWE
CWE-308

Use of Single-factor Authentication