CVE-2025-22956 – OPSI Windomain Property Disclosure

The following table lists the changes that have been made to the
CVE-2025-22956 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Sep. 08, 2025

    Action Type Old Value New Value
    Added Description OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalation if any ProductPropertyState contains a secret only intended to be accessible by a subset of clients. One example of this is a domain join account password for the windomain package.
    Added Reference https://opsi.org/en/product/releases/#4.3-20250129054911
Share the Post:

Related Posts