6.5
CVE-2025-11681
- EPSS 0.39%
- Veröffentlicht 17.11.2025 11:30:25
- Zuletzt bearbeitet 07.10.2026 21:10:00
- Erkennungen
Denial of Service condition in M-Files Server
Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
M-files ≫ M-files Server SwEdition lts Version < 25.2.14524.13
M-files ≫ M-files Server SwEdition - Version < 25.11.15392.1
M-files ≫ M-files Server SwEdition lts Version >= 25.8.15085.13 < 25.8.15085.17
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.315 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| security@m-files.com | 7.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://product.m-files.com/security-advisories/cve-2025-11681/
https://empower.m-files.com/security-advisories/CVE-2025-11681