5.9
CVE-2025-27244
- EPSS 0.19%
- Veröffentlicht 02.04.2025 04:15:35
- Zuletzt bearbeitet 02.04.2025 14:58:07
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
AssetView and AssetView CLOUD contain an issue with acquiring sensitive information from sent data to the developer. If exploited, sensitive information may be obtained by a remote unauthenticated attacker.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerHammock Corporation
≫
Produkt
AssetView
Version
prior to Ver 13.2.4.3408 (13.2.4O)
Status
affected
HerstellerHammock Corporation
≫
Produkt
AssetView CLOUD
Version
prior to Ver 13.2.4.3408 (13.2.4O)
Status
affected
HerstellerHammock Corporation
≫
Produkt
AssetView CLOUD
Version
prior to Ver 13.3.4.3004 (13.3.4K)
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.404 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| vultures@jpcert.or.jp | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-201 Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.