CVE-2025-2538: BUG-000174336
A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remote unauthenticated attacker to gain administrative access to the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Esri Portal for ArcGISto a version that resolves this vulnerability.Fixed in 11.4Patch BUG-000174336 - Operational
Review the Portal deployment pattern associated with BUG-000174336 and rotate any exposed credentials used by Esri Portal for ArcGIS after applying the fix.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2538?
CVE-2025-2538 is classified as a high-severity vulnerability due to the potential for unauthorized password resets on the admin account.
How do I fix CVE-2025-2538?
To mitigate CVE-2025-2538, ensure you apply the latest security patches provided by Esri for ArcGIS Enterprise.
What does CVE-2025-2538 affect?
CVE-2025-2538 affects the Portal component of specific ArcGIS Enterprise deployments.
Who is affected by CVE-2025-2538?
Organizations using Esri ArcGIS Enterprise with the vulnerable Portal configuration are at risk from CVE-2025-2538.
What could an attacker do by exploiting CVE-2025-2538?
An attacker exploiting CVE-2025-2538 could reset the password for the built-in admin account, potentially gaining unauthorized access.