CVE-2025-22956

9.8

OPSI · OPSI

OPSI versions prior to 4.3 allow unauthorized clients to retrieve sensitive ProductPropertyState data from other clients, potentially leading to privilege escalation.

Executive summary

A critical information disclosure vulnerability in OPSI versions prior to 4.3 allows unauthorized clients to access sensitive state data, facilitating potential privilege escalation.

Vulnerability

The vulnerability involves an improper access control flaw where unauthenticated clients can retrieve ProductPropertyState information belonging to other clients. This unauthorized access can expose sensitive secrets, leading to potential privilege escalation.

Business impact

Successful exploitation allows an attacker to gain access to sensitive properties that may contain credentials or configuration secrets. With a CVSS score of 9.8, this flaw represents a critical threat to the security posture of the OPSI management environment, potentially compromising the integrity and confidentiality of the entire managed client fleet.

Remediation

Immediate Action: Upgrade all OPSI installations to version 4.3 or later to remediate the access control flaw.

Proactive Monitoring: Review OPSI access logs for unusual patterns of client requests for property states, especially those originating from unauthorized or unexpected client IDs.

Compensating Controls: Isolate the OPSI management network and restrict access to the OPSI web service to trusted internal IP ranges only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability, combined with its potential for privilege escalation, necessitates an immediate update to version 4.3. Administrators should prioritize this transition to ensure that client-to-client data access is properly restricted.