CVE-2025-12420 (CNNVD-202601-1807)
中文标题:
ServiceNow AI Platform 安全漏洞
英文标题:
A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticat
漏洞描述
中文描述:
ServiceNow AI Platform是美国ServiceNow公司的一款AI智能平台。 ServiceNow AI Platform存在安全漏洞,该漏洞源于未经验证的用户可冒充其他用户并执行其有权执行的操作。
英文描述:
A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a relevant security update to hosted instances in October 2025. Security updates have also been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Additionally, the vulnerability is addressed in the listed Store App versions. We recommend that customers promptly apply an appropriate security update or upgrade if they have not already done so.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| ServiceNow | Now Assist AI Agents | - | ≤ 5.1.17 | - |
cpe:2.3:a:servicenow:now_assist_ai_agents:*:*:*:*:*:*:*:*
|
| ServiceNow | Virtual Agent API | - | < 3.15.2 | - |
cpe:2.3:a:servicenow:virtual_agent_api:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
nvd.nist.gov
CVSS评分详情
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/S:N/AU:Y/R:U/V:C/RE:H/U:Amber
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| NVD | nvd_CVE-2025-12420 |
2026-01-13 03:00:04 | 2026-01-13 06:36:16 |
| CVE | cve_CVE-2025-12420 |
2026-01-13 07:32:17 | 2026-01-13 07:40:53 |
| CNNVD | cnnvd_CNNVD-202601-1807 |
2026-01-15 01:52:30 | 2026-01-15 01:53:09 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202601-1807
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.UNKNOWN -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 9.3
- cvss_vector: 未提取 -> CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/S:N/AU:Y/R:U/V:C/RE:H/U:Amber
- cvss_version: 未提取 -> 4.0
- affected_products_count: 0 -> 2
- data_sources: ['nvd'] -> ['cve', 'nvd']