CVE-2025-35115

8.1

Agiloft · Agiloft

Agiloft Release 28 downloads critical system packages over insecure HTTP, allowing potential man-in-the-middle attackers to replace or modify package contents.

Executive summary

A critical vulnerability in Agiloft allows attackers to intercept and manipulate system package downloads, potentially leading to full system compromise.

Vulnerability

This vulnerability involves a failure to verify the integrity of downloaded code (CWE-494) when retrieving system packages via insecure HTTP. This flaw allows an unauthenticated attacker in a man-in-the-middle position to inject malicious payloads into the update process.

Business impact

The ability for an attacker to replace or modify critical system packages poses a severe risk to the confidentiality, integrity, and availability of the Agiloft environment. Given the high CVSS score of 8.1, this vulnerability could facilitate unauthorized remote code execution, potentially leading to complete system takeover and significant data exposure.

Remediation

Immediate Action: Upgrade all instances of Agiloft to Release 30 or later to ensure package downloads are handled over secure channels with integrity checks.

Proactive Monitoring: Monitor network traffic for unusual HTTP requests originating from the Agiloft server, particularly those directed at package repositories or update endpoints.

Compensating Controls: Deploy a secure proxy or VPN to force traffic through encrypted tunnels, and implement strict egress filtering to limit the server's ability to communicate over unencrypted HTTP channels.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk associated with this vulnerability is significant due to the potential for unauthorized code execution within the system update pipeline. IT administrators must prioritize the transition to Release 30 immediately to eliminate the exposure to man-in-the-middle attacks. Failure to patch leaves the environment vulnerable to persistent compromise via malicious updates.

More Agiloft CVEs

Sources

Originally found and disclosed by Matthew Galligan, CISA Rapid Action Force (RAF), per the CVE Program record.