7.5
CVE-2025-46705
- EPSS 0.46%
- Veröffentlicht 05.11.2025 14:56:55
- Zuletzt bearbeitet 07.11.2025 20:02:36
- Erkennungen
A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Entrouvert ≫ Lasso Version 2.5.1
Entrouvert ≫ Lasso Version 2.8.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.46% | 0.372 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Cisco Talos | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-617 Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
https://talosintelligence.com/vulnerability_reports/TALOS-2025-2196
https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2196