CVE Vulnerabilities

CVE-2025-43485

Insertion of Sensitive Information into Log File

Published: Jul 23, 2025 | Modified: Oct 02, 2025
CVSS 3.x
4.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could potentially allow a privileged user to retrieve credentials from the log files. HP has addressed the issue in the latest software update.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Poly_clariti_manager Hp * 10.12.2 (excluding)

Potential Mitigations

References