CVE-2025-0619: Unsafe stored password recovery
Published Jan 23, 2025
·Updated
Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords
Affected Software
2 affected components
M-Files M-Files server<25.1
M-Files M-Files server<25.1.14445.5
Event History
Jan 23, 2025
CVE Published
via MITRE·11:07 AM
Data Sourced
via MITRE·11:07 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0619?
CVE-2025-0619 is considered a high-severity vulnerability due to its potential for unauthorized password recovery by highly privileged users.
2
How do I fix CVE-2025-0619?
To mitigate CVE-2025-0619, upgrade to M-Files Server version 25.1 or later where the vulnerability has been addressed.
3
What software is affected by CVE-2025-0619?
CVE-2025-0619 affects M-Files Server versions prior to 25.1.
4
What kind of information can be compromised due to CVE-2025-0619?
CVE-2025-0619 allows a highly privileged user to recover sensitive external connector passwords from server configuration.
5
How can I verify if I am using a vulnerable version related to CVE-2025-0619?
To check for CVE-2025-0619, verify that your M-Files Server version is below 25.1.