BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or
series 5 prior to v9.0.166 contain an execution with unnecessary
privileges vulnerability, allowing for privilege escalation on the
device once code execution has been obtained.
Metrics
Affected Vendors & Products
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 08 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 May 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 contain an execution with unnecessary privileges vulnerability, allowing for privilege escalation on the device once code execution has been obtained. | |
| Title | BrightSign Players Execution with Unnecessary Privileges | |
| Weaknesses | CWE-250 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published: 2025-05-07T20:18:22.457Z
Updated: 2025-05-08T14:04:48.853Z
Reserved: 2025-04-24T17:54:29.059Z
Link: CVE-2025-3925
Updated: 2025-05-08T14:04:45.517Z
Status : Awaiting Analysis
Published: 2025-05-07T21:16:03.897
Modified: 2025-05-08T14:39:09.683
Link: CVE-2025-3925
No data.