Published:2025/03/25 Last Updated:2025/03/25
JVN#26321838
Multiple vulnerabilities in AssetView
Overview
AssetView provided by Hammock Corporation contains multiple vulnerabilities.
Products Affected
- AssetView versions prior to Ver 13.2.4.3408 (13.2.4O)
- AssetView CLOUD
- Versions prior to Ver 13.2.4.3408 (13.2.4O)
- Versions prior to Ver 13.3.4.3004 (13.3.4K)
Description
AssetView provided by Hammock Corporation contains multiple vulnerabilities listed below.
- Missing authentication for critical function (CWE-306)
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N Base Score 8.2
- CVE-2025-25060
- Acquiring sensitive information from sent data to the developer (CWE-201)
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Base Score 5.9
- CVE-2025-27244
- This analysis assumes a man-in-the-middle attack being conducted by an attacker who can read communication between the product and the developer.
Impact
- The files on the server where the product is running may be obtained and/or deleted by a remote unauthenticated attacker (CVE-2025-25060)
- Sensitive information may be obtained by a remote unauthenticated attacker (CVE-2025-27244)
Solution
Update the Software
For AseetView:
Apply the appropriate update according to the information provided by the developer.
Users of AssetView prior to Ver 13.2.0 should contact Support Group of the developer.
For AseetView CLOUD:
Users of AssetView CLOUD should contact Support Group of the developer.
Refer to the infomation provided by the developer for details.
Vendor Status
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Takao Kondo of VeriServe Corporation reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
JPCERT Alert |
|
JPCERT Reports |
|
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2025-25060 |
CVE-2025-27244 |
|
JVN iPedia |
JVNDB-2025-000019 |