9.8
CVE-2025-61932
- EPSS 3.67%
- Veröffentlicht 20.10.2025 07:25:39
- Zuletzt bearbeitet 23.10.2025 13:00:14
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Motex ≫ Lanscope Endpoint Manager SwEditionon-premise Version < 9.3.2.7
Motex ≫ Lanscope Endpoint Manager SwEditionon-premise Version >= 9.3.3.0 < 9.3.3.9
Motex ≫ Lanscope Endpoint Manager SwEditionon-premise Version >= 9.4.0.0 < 9.4.0.5
Motex ≫ Lanscope Endpoint Manager SwEditionon-premise Version >= 9.4.1.0 < 9.4.1.5
Motex ≫ Lanscope Endpoint Manager SwEditionon-premise Version >= 9.4.2.0 < 9.4.2.6
Motex ≫ Lanscope Endpoint Manager SwEditionon-premise Version >= 9.4.3.0 < 9.4.3.8
Motex ≫ Lanscope Endpoint Manager SwEditionon-premise Version >= 9.4.4.0 < 9.4.4.6
Motex ≫ Lanscope Endpoint Manager SwEditionon-premise Version >= 9.4.5.0 < 9.4.5.4
Motex ≫ Lanscope Endpoint Manager SwEditionon-premise Version >= 9.4.6.0 < 9.4.6.3
Motex ≫ Lanscope Endpoint Manager SwEditionon-premise Version >= 9.4.7.0 <= 9.4.7.1
22.10.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog
Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability
SchwachstelleMotex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packets.
BeschreibungApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.67% | 0.877 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| vultures@jpcert.or.jp | 9.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| vultures@jpcert.or.jp | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-940 Improper Verification of Source of a Communication Channel
The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.