CVE-2025-40806: Medium severity Gridscale X Prepay vulnerability
A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to user enumeration due to distinguishable responses. This could allow an unauthenticated remote attacker to determine if a user is valid or not, enabling a brute force attack with valid users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40806?
CVE-2025-40806 is considered a moderate severity vulnerability due to its potential for user enumeration and subsequent brute force attacks.
How do I fix CVE-2025-40806?
To fix CVE-2025-40806, upgrade to Gridscale X Prepay version 4.2.1 or later.
What systems are affected by CVE-2025-40806?
CVE-2025-40806 affects all versions of Gridscale X Prepay prior to version 4.2.1.
Can CVE-2025-40806 be exploited remotely?
Yes, CVE-2025-40806 can be exploited remotely by unauthenticated attackers.
What type of attack can CVE-2025-40806 facilitate?
CVE-2025-40806 can facilitate user enumeration and enable brute force attacks against valid user accounts.