
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68164 is a port enumeration vulnerability in JetBrains TeamCity affecting all versions before 2025.11. The flaw allows high-privileged (administrative) users to enumerate open ports on internal network hosts via the Perforce version control connection test functionality. It was published on December 16, 2025, with a patch released in TeamCity 2025.11. The vulnerability carries a CVSS v3.1 base score of 2.7 (Low), reflecting its requirement for high privileges and limited confidentiality impact (JetBrains Advisory, Red Hat CVE).
The root cause is classified as CWE-203 (Observable Discrepancy), where differences in server responses to the Perforce connection test can be observed to infer whether a given port is open or closed on a target host. An authenticated administrator can craft connection test requests targeting arbitrary host/port combinations and use the discrepancy in responses to enumerate network services. This constitutes a Server-Side Request Forgery (SSRF)-adjacent information disclosure, as the TeamCity server acts as a proxy for network probing. No public proof-of-concept or detailed technical write-up has been identified beyond the vendor advisory (JetBrains Advisory, Red Hat CVE).
Successful exploitation allows an attacker with administrative access to TeamCity to conduct internal network port enumeration, potentially mapping open services and infrastructure behind the TeamCity server's network perimeter. The impact is limited to low confidentiality disclosure — no integrity or availability impact is present. While the direct damage is minimal, the reconnaissance capability could assist a malicious insider or compromised admin account in identifying targets for further lateral movement (JetBrains Advisory, Red Hat CVE).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept for CVE-2025-68164. The vulnerability requires high privileges (administrative access to TeamCity), significantly limiting the attacker pool. The EPSS score is extremely low at 0.000020, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (JetBrains Advisory, Red Hat CVE).
JetBrains has addressed this vulnerability in TeamCity version 2025.11; upgrading to this version or later is the recommended remediation (JetBrains Advisory). As interim mitigations, organizations should restrict administrative access to TeamCity to only trusted personnel, implement network segmentation to limit the TeamCity server's outbound connectivity to only required VCS hosts, and audit administrative actions within the TeamCity environment. No configuration-based workaround that fully eliminates the vulnerability without upgrading has been published.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."