CVE-2025-15624Disclosure(sparxsystems / pro_cloud_server)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.  In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, Pro Cloud Server creates local passwords to the users and stores them in plaintext.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-256

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pro_cloud_server

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-17); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
pro_cloud_server

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-17: 3Mentions · 2026-06-02: 1Technical Details · 2026-04-17: 2Technical Details · 2026-06-02: 104-1706-02
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-173
Disclosure2General1
2026-06-021
Disclosure1
Full discourse4 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-15624: Plaintext Storage of a Password ... OpenID bypass creates local plaintext passwords - classic enterprise auth fail that turns SSO security theater into cre... https://zerodaysignal.com/vulnerability/CVE-2025-15624 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2025-15624, detailing a plain-text password storage issue via an OpenID bypass and links to a writeup, but does not provide PoC, exploit code, or patch information.

    00010556
    218 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Sparx Pro Cloud Server – Plaintext Password Storage (CWE-256) – #CVE-2025-15624 (Critical) -DC-Jun2026-114 https://dailycve.com/sparx-pro-cloud-server-plaintext-password-storage-cwe-256-cve-2025-15624-critical-dc-jun2026-114/

    Post summary

    A new vulnerability, CVE‑2025‑15624, involving plaintext password storage (CWE‑256) has been disclosed, with basic details such as severity and CWE identifier, but no PoC, exploit, or patch information is provided.

    0000025
    209 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-15624 Plaintext Password Storage Vulnerability in Sparx Systems... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-15624 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE-2025-15624—a plaintext password storage flaw in Sparx Systems—providing links to a vulnerability detail page but offering no technical, exploit, or remediation information.

    00000189
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2025-15624 Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.  In a setup where OpenID is used as the primary method of authenticati… https://www.cve.org/CVERecord?id=CVE-2025-15624

    Post summary

    The text provides a brief mention of CVE‑2025‑15624, identifying it as a plaintext password storage issue in Sparx Pro Cloud Server, but offers no additional details on exploitation, patching, or proof-of-concept.

    00000191
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsparxsystemspro_cloud_server6.0.163--

Explore more