CVE-2025-43720

Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.
Configurations

Configuration 1 (hide)

cpe:2.3:a:h-mdm:headwind_mdm:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-07-21 17:15

Updated : 2025-08-07 18:16


NVD link : CVE-2025-43720

Mitre link : CVE-2025-43720

CVE.ORG link : CVE-2025-43720


JSON object : View

Products Affected

h-mdm

  • headwind_mdm
CWE
CWE-862

Missing Authorization