CVE-2025-30235: Race Condition
Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 is intended to disable accounts that have had more than 10 failed authentication attempts, but instead allows hundreds of failed authentication attempts, because concurrent attempts are mishandled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Shearwater SecurEnvoy SecurAccessto a version that resolves this vulnerability.Fixed in 9.4.515
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30235?
CVE-2025-30235 is a high-severity vulnerability that allows for excessive failed authentication attempts due to mishandling of concurrent logins.
How do I fix CVE-2025-30235?
To fix CVE-2025-30235, upgrade Shearwater SecurEnvoy SecurAccess Enrol to version 9.4.515 or later.
What impact does CVE-2025-30235 have on security?
CVE-2025-30235 can lead to account enumeration and increased risk of unauthorized access due to unregulated failed authentication attempts.
Who is affected by CVE-2025-30235?
Organizations using Shearwater SecurEnvoy SecurAccess Enrol versions prior to 9.4.515 are affected by CVE-2025-30235.
What are the potential exploit techniques for CVE-2025-30235?
Attackers may exploit CVE-2025-30235 by executing multiple concurrent login attempts to bypass the account lockout mechanism.