Authorization Bypass in VHS Electronic Software's ACE Center
CVE-2025-8884

5.5MEDIUM

Key Information:

Vendor
CVE Published:
20 October 2025

What is CVE-2025-8884?

The ACE Center software from VHS Electronic Software Ltd. Co. contains a vulnerability that allows users to bypass authorization through controlled keys. This flaw can lead to unauthorized access, enabling privilege abuse and exploitation of trusted identifiers. The specific versions affected range from 3.10.100.1768 up to but not including 3.10.161.2255. It is crucial for users to assess their environments and apply necessary updates to mitigate potential risks.

Affected Version(s)

ACE Center 3.10.100.1768 < 3.10.161.2255

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Can Nesimi ARI
.
CVE-2025-8884 : Authorization Bypass in VHS Electronic Software's ACE Center