6.8
CVE-2025-25002
- EPSS 1.37%
- Veröffentlicht 08.04.2025 17:23:42
- Zuletzt bearbeitet 16.01.2026 14:07:36
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Azure Local Cluster Version < 2411.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.37% | 0.799 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.7 | 2.1 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| secure@microsoft.com | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.