CVE-2025-9317: AVEVA Edge Use of a Broken or Risky Cryptographic Algorithm
The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache files to reverse engineer Edge users' app-native or Active Directory passwords through computational brute-forcing of weak hashes.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9317?
CVE-2025-9317 is considered a high-severity vulnerability due to the potential for sensitive password exposure.
How do I fix CVE-2025-9317?
To mitigate CVE-2025-9317, users should update to the latest version of AVEVA Edge beyond 2023 R2.
Who is affected by CVE-2025-9317?
CVE-2025-9317 affects any installations of AVEVA Edge versions 2023 R2 and prior.
What can an attacker do with CVE-2025-9317?
An attacker with read access to specific files can exploit CVE-2025-9317 to perform computational brute-forcing of weak password hashes.
What types of hashes are vulnerable in CVE-2025-9317?
CVE-2025-9317 specifically targets weak hashes used for app-native or Active Directory passwords.