CVE-2025-4971: Broadcom Automic Automation Agent Unix privilege escalation
Published May 19, 2025
·Updated
Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges.
Affected Software
1 affected component
Broadcom Automic Automation Agent Unix<24.3.0 HF4, <21.0.13 HF1
Event History
May 19, 2025
CVE Published
via MITRE·11:42 PM
Data Sourced
via MITRE·11:42 PM
DescriptionWeakness
May 20, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
May 29, 2025
Exploit Published
12:00 AM
Known Exploited
10:17 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-4971?
CVE-2025-4971 has a medium severity rating due to its potential for privilege escalation by low-privileged users.
2
How do I fix CVE-2025-4971?
To fix CVE-2025-4971, update the Broadcom Automic Automation Agent Unix to versions 24.3.0 HF4 or 21.0.13 HF1 or later.
3
What systems are affected by CVE-2025-4971?
CVE-2025-4971 affects Broadcom Automic Automation Agent Unix versions prior to 24.3.0 HF4 and 21.0.13 HF1.
4
Who can exploit CVE-2025-4971?
CVE-2025-4971 can be exploited by low privileged users who have execution rights on the agent executable.
5
What type of vulnerability is CVE-2025-4971?
CVE-2025-4971 is a privilege escalation vulnerability that allows unauthorized access to higher-level permissions.