CVE-2025-35115
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
26/08/2025
Last modified:
26/08/2025
Description
Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Middle position could replace or modify the contents of the download URL. Users should upgrade to Agiloft Release 30.
Impact
Base Score 4.0
9.20
Severity 4.0
CRITICAL
Base Score 3.x
8.10
Severity 3.x
HIGH