CVE Explorer
CVE-2025-64483
Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configuration in certain configurations allows authenticated users with read-only API roles to retrieve agent enrollment credentials through the /utils/configuration endpoint. These credentials can be used to register new agents within the same Wazuh tenant without requiring elevated permissions through the UI. This issue has been patched in version 4.13.0.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"wazuh-dashboard-plugins","vendor":"wazuh","versions":[{"status":"affected","version":">= 4.9.0, < 4.13.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4991b84cfcc209a5ba109871e127eb9cc03c800071f5c7c6d95518f21c09851d · sha256:3e0ebac821e14ff5… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.3,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4991b84cfcc209a5ba109871e127eb9cc03c800071f5c7c6d95518f21c09851d · sha256:3e0ebac821e14ff5… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4991b84cfcc209a5ba109871e127eb9cc03c800071f5c7c6d95518f21c09851d · sha256:3e0ebac821e14ff5… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/wazuh/wazuh-dashboard-plugins/commit/eac859f1ad0bf5eb8b0dbc7ea7eeef4bd22c3722","tags":["x_refsource_MISC"],"url":"https://github.com/wazuh/wazuh-dashboard-plugins/commit/eac859f1ad0bf5eb8b0dbc7ea7eeef4bd22c3722"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4991b84cfcc209a5ba109871e127eb9cc03c800071f5c7c6d95518f21c09851d · sha256:3e0ebac821e14ff5… · /containers/cna/references/1
{"name":"https://github.com/wazuh/wazuh-dashboard-plugins/security/advisories/GHSA-gwf3-8gm3-qrmj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/wazuh/wazuh-dashboard-plugins/security/advisories/GHSA-gwf3-8gm3-qrmj"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4991b84cfcc209a5ba109871e127eb9cc03c800071f5c7c6d95518f21c09851d · sha256:3e0ebac821e14ff5… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.