7.5
CVE-2025-13651
- EPSS 0.4%
- Veröffentlicht 11.02.2026 09:15:50
- Zuletzt bearbeitet 26.03.2026 17:56:48
- Quelle ffb98d57-deaa-4918-a669-5225cc
- CVE-Watchlists
- Unerledigt
LEAK OF SENSITIVE INFORMATION ON MICROCOM'S ZEUSWEB
Exposure of Sensitive System Information to an Unauthorized Actor vulnerability in Microcom ZeusWeb allows Web Application Fingerprinting of sensitive data. This issue affects ZeusWeb: 6.1.31.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microcom360 ≫ Zeusweb Version >= 6.1.31
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.316 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| ffb98d57-deaa-4918-a669-5225ccc13e39 | 6.9 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
https://www.hackrtu.com/blog/CNA-HRTU-0001/
https://www.microcom360.com/servicio-zeus-web/
https://zeus.microcom.es:4040/
https://www.hackrtu.com/blog/CNA-CVE-2025-13651/