4.3
CVE-2025-26849
- EPSS 0.23%
- Veröffentlicht 04.03.2025 09:15:10
- Zuletzt bearbeitet 07.07.2025 18:27:52
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions. This key can be used to decrypt inventory files that contain sensitive information such as firewall rules.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.14 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cve@mitre.org | 4.3 | 2.5 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
|
CWE-1394 Use of Default Cryptographic Key
The product uses a default cryptographic key for potentially critical functionality.
https://docs.docusnap.com/en/release-notes/changelog/
https://www.redteam-pentesting.de/en/advisories/rt-sa-2024-012/