Resource exhaustion in Edge Orchestrator for Intel Tiber Edge Platform - CVE-2025-20616
Published: May 16, 2025
Vulnerability identifier: #VU109261
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20616
CWE-ID: CWE-400
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote user on the local network can trigger resource exhaustion and gain elevated privileges on the target system.
Affected software
Edge Orchestrator for Intel Tiber Edge Platform
How to mitigate CVE-2025-20616
Install updates from vendor's website.
Edge Orchestrator for Intel Tiber Edge Platform - update to 24.11