« Back to list

CVE-2025-9912

Status: Awaiting AnalysisMedium (6.3)—

Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2025-9912",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-9912",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-16T12:28:34.738391Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
      "affectedData": [
        {
          "vendor": "Nokia",
          "product": "Nokia SR Linux",
          "versions": [
            {
              "status": "affected",
              "version": "< 23.10.8"
            },
            {
              "status": "affected",
              "version": "< 24.10.6"
            },
            {
              "status": "affected",
              "version": "< 25.7.2"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Nokia",
          "product": "Nokia SR Linux",
          "versions": [
            {
              "status": "unaffected",
              "version": "23.10.8"
            },
            {
              "status": "unaffected",
              "version": "24.10.6"
            },
            {
              "status": "unaffected",
              "version": "25.7.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-16T08:16:23.627",
  "references": [
    {
      "url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-9912/",
      "source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege."
    },
    {
      "lang": "es",
      "value": "Nokia SR Linux es vulnerable a una vulnerabilidad de escalada de privilegios local. La explotación exitosa de esta vulnerabilidad podría permitir a un usuario autenticado ejecutar comandos arbitrarios con privilegios de superusuario."
    }
  ],
  "lastModified": "2026-09-30T21:10:00.190",
  "sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}