CVE-2025-41086
EUVD-2025-20024402.12.2025, 14:16
Vulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be generated, bypassing any usage restrictions. The validator uses an insecure checksum algorithm; knowing this algorithm and the format of the license lines, an attacker can recalculate the checksum and generate a valid license to grant themselves full privileges without credentials or access to the source code, allowing them unrestricted access to GAMS's mathematical models and commercial solvers.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gams | gams | 𝑥 < 48.7.0 |
| gams | gams | 49.1.0 ≤ 𝑥 < 49.7.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration