Lack of protection against brute force attacks in Valmet DNA visualization in DNA Operate. The possibility to make an arbitrary number of login attempts without any rate limit gives an attacker an increased chance of guessing passwords and then performing switching operations.
CVE ID: CVE-2025-0417
CVSS Base Severity: HIGH
CVSS Base Score: 7.0
CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/AU:Y/R:A/V:D/RE:L/U:Green
Vendor: Valmet
Product: Valmet DNA
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 3.14% (scored less or equal to compared to others)
EPSS Date: 2025-04-30 (when was this score calculated)