{"id":"CVE-2025-12381","title":"Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, Parameter Injection.\n\nA local user with access to the command line may escalate their privileges by abusing the parame…","summary":"Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, Parameter Injection.\n\nA local user with access to the command line may escalate their privileges by abusing the parame…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-269"],"vendor":"algosec","product":"firewall_analyzer","affected":["firewall_analyzer = a33.0","firewall_analyzer = a33.10"],"published":"2025-12-09","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:10:01.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-12381","references":[{"url":"https://techdocs.algosec.com/en/cves/Content/tech-notes/cves/cve-2025-12381.htm","label":"security.vulnerabilities@algosec.com"}],"tags":["nvd"],"epss":0.0016,"epssPercentile":0.04529,"ingestedAt":"2026-10-07T20:46:46.782Z","slug":"CVE-2025-12381","body":"## Overview\n\nImproper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, Parameter Injection.\n\nA local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. \nThis issue affects Firewall Analyzer: A33.0, A33.10.\n\n## Affected\n\n- `firewall_analyzer = a33.0`\n- `firewall_analyzer = a33.10`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}