Input validation error in Edge Orchestrator for Intel Tiber Edge Platform - CVE-2025-27537
Published: August 25, 2025
Vulnerability identifier: #VU114409
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-27537
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the target system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote user on the local network can pass specially crafted input to the application and gain elevated privileges on the system.
Affected software
Edge Orchestrator for Intel Tiber Edge Platform
How to mitigate CVE-2025-27537
Install updates from vendor's website.
Edge Orchestrator for Intel Tiber Edge Platform - update to 24.11.1