CVE-2025-48611: High-Severity Vulnerability (CVSS 10.0)
Summary
In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. ...
Threat Analysis
A critical-severity vulnerability has been identified with a CVSS score of 10.0. In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Organizations should review their systems for affected components and apply security patches as soon as they become available. This vulnerability could potentially allow attackers to compromise systems if left unpatched.