5.8
CVE-2025-1787
- EPSS 0.01%
- Veröffentlicht 24.02.2026 18:44:36
- Zuletzt bearbeitet 26.02.2026 18:00:15
- Quelle security@genetec.com
- CVE-Watchlists
- Unerledigt
Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin privileged, Windows user could exploit this vulnerability to gain elevated privileges in the Genetec Update Service. Could be combined with CVE-2025-1789 to achieve low privilege escalation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Genetec ≫ Genetec Update Service Version < 2.10.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.007 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.2 | 0.8 | 3.4 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
|
| security@genetec.com | 5.8 | 0 | 0 |
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:H/IR:H/AR:H/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:H/MVI:H/MVA:H/MSC:X/MSI:H/MSA:H/S:P/AU:N/R:X/V:C/RE:X/U:X
|
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.