CVE-2025-43720

Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.
Configurations

Configuration 1 (hide)

cpe:2.3:a:h-mdm:headwind_mdm:*:*:*:*:*:*:*:*

History

07 Aug 2025, 18:16

Type Values Removed Values Added
CPE cpe:2.3:a:h-mdm:headwind_mdm:*:*:*:*:*:*:*:*
Summary
  • (es) Headwind MDM anterior a la versión 5.33.1 permite el acceso a los detalles de configuración a usuarios no autorizados. El perfil de configuración se expone al rol de usuario Observador, lo que revela la contraseña necesaria para salir del perfil del dispositivo controlado por MDM.
First Time H-mdm headwind Mdm
H-mdm
References () https://github.com/h-mdm/hmdm-server/commit/19e4a63f732c99064444df7e8c61b4f01df362e8 - () https://github.com/h-mdm/hmdm-server/commit/19e4a63f732c99064444df7e8c61b4f01df362e8 - Patch
References () https://github.com/h-mdm/hmdm-server/compare/v5.32.1...v5.33.1 - () https://github.com/h-mdm/hmdm-server/compare/v5.32.1...v5.33.1 - Patch
References () https://www.periculo.co.uk/cyber-security-blog/how-our-pen-tester-found-a-critical-vulnerability-cve-2025-43720 - () https://www.periculo.co.uk/cyber-security-blog/how-our-pen-tester-found-a-critical-vulnerability-cve-2025-43720 - Third Party Advisory

22 Jul 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-862

21 Jul 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 17:15

Updated : 2025-08-07 18:16


NVD link : CVE-2025-43720

Mitre link : CVE-2025-43720

CVE.ORG link : CVE-2025-43720


JSON object : View

Products Affected

h-mdm

  • headwind_mdm
CWE
CWE-862

Missing Authorization