8.1
CVE-2025-35940
- EPSS 0.33%
- Veröffentlicht 10.06.2025 20:27:51
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle vulnreport@tenable.com
- CVE-Watchlists
- Unerledigt
Hard-coded ArchiverSpaApi JWT Signing Key
The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected ArchiverSpaApi URL endpoints.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGFI
≫
Produkt
Archiver
Default Statusunaffected
Version <=
15.8
Version
15.7
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.556 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| vulnreport@tenable.com | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.