mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-09-17 18:45:49 +00:00
64 lines
2.0 KiB
JSON
64 lines
2.0 KiB
JSON
{
|
|
"id": "CVE-2025-30236",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2025-03-19T06:15:16.243",
|
|
"lastModified": "2025-03-19T07:15:34.313",
|
|
"vulnStatus": "Received",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authentication through only a six-digit TOTP code (skipping a password check) if an HTTP POST request contains a SESSION parameter."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "La inscripci\u00f3n a Shearwater SecurEnvoy SecurAccess anterior a la versi\u00f3n 9.4.515 permite la autenticaci\u00f3n \u00fanicamente a trav\u00e9s de un c\u00f3digo TOTP de seis d\u00edgitos (omitiendo la verificaci\u00f3n de contrase\u00f1a) si una solicitud HTTP POST contiene un par\u00e1metro SESSION."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "cve@mitre.org",
|
|
"type": "Secondary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
|
|
"baseScore": 8.6,
|
|
"baseSeverity": "HIGH",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "NONE",
|
|
"scope": "CHANGED",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "HIGH",
|
|
"availabilityImpact": "NONE"
|
|
},
|
|
"exploitabilityScore": 3.9,
|
|
"impactScore": 4.0
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "cve@mitre.org",
|
|
"type": "Secondary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-472"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://reserge.org/probabilistically-breaking-securenvoy-totp/",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "https://securenvoy.com/wp-content/uploads/2025/03/Release-Notes-9.4.515.pdf",
|
|
"source": "cve@mitre.org"
|
|
}
|
|
]
|
|
} |