{"id":"CVE-2025-27258","title":"Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.","summary":"Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-284"],"vendor":"ericsson","product":"network_manager","affected":["network_manager < 25.1"],"patched":["network_manager 25.1"],"published":"2025-10-13","updated":"2026-10-08","sourceUpdated":"2026-10-08T12:10:00.217","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-27258","references":[{"url":"https://www.ericsson.com/en/about-us/security/psirt/security-bulletin-enm-october-2025","label":"85b1779b-6ecd-4f52-bcc5-73eac4659dcf"}],"tags":["nvd"],"epss":0.00298,"epssPercentile":0.20634,"ingestedAt":"2026-10-08T11:31:27.350Z","slug":"CVE-2025-27258","body":"## Overview\n\nEricsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.\n\n## Affected\n\n- `network_manager < 25.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `network_manager 25.1`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}