We found results for “”
CVE-2025-66432
Good to know:
Date: November 29, 2025
In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.
Severity Score
Severity Score
Weakness Type (CWE)
Unprotected Alternate Channel
CWE-420Top Fix
Upgrade Version
Upgrade to version https://github.com/oxidecomputer/omicron.git - rel/v17.1/rc0
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


