Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control of Web parameter. If exploited, a user of the product may escalate the privilege and access data that the user do not have permission to view by altering the parameters of the search function.
History

Thu, 21 Aug 2025 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 05:15:00 +0000

Type Values Removed Values Added
Description Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control of Web parameter. If exploited, a user of the product may escalate the privilege and access data that the user do not have permission to view by altering the parameters of the search function.
Weaknesses CWE-472
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2025-08-20T04:57:37.466Z

Updated: 2025-08-20T17:39:58.306Z

Reserved: 2025-07-24T23:48:13.065Z

Link: CVE-2025-54551

cve-icon Vulnrichment

Updated: 2025-08-20T17:37:57.611Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-20T05:15:28.057

Modified: 2025-08-20T14:39:07.860

Link: CVE-2025-54551

cve-icon Redhat

No data.