5.4
CVE-2025-50325
- EPSS 0.29%
- Veröffentlicht 22.07.2026 00:00:00
- Zuletzt bearbeitet 24.07.2026 20:17:01
- CVE-Watchlists
- Unerledigt
BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.208 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
|
CWE-693 Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
https://en.bandisoft.com/bandizip/help/zone-identifier/
https://en.bandisoft.com/bandizip/history/
https://github.com/OV-0-VO/Public-references/blob/main/CVE-2025-50325.md