Input validation error in Edge Orchestrator for Intel Tiber Edge Platform - CVE-2025-27537

 

Input validation error in Edge Orchestrator for Intel Tiber Edge Platform - CVE-2025-27537

Published: August 25, 2025


Vulnerability identifier: #VU114409
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-27537
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the target system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote user on the local network can pass specially crafted input to the application and gain elevated privileges on the system.


Affected software

Edge Orchestrator for Intel Tiber Edge Platform

How to mitigate CVE-2025-27537

Install updates from vendor's website.

Edge Orchestrator for Intel Tiber Edge Platform - update to 24.11.1

External References

Related Security Bulletins