9.8

CVE-2025-61932

Warnung
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MotexLanscope Endpoint Manager SwEditionon-premise Version < 9.3.2.7
MotexLanscope Endpoint Manager SwEditionon-premise Version >= 9.3.3.0 < 9.3.3.9
MotexLanscope Endpoint Manager SwEditionon-premise Version >= 9.4.0.0 < 9.4.0.5
MotexLanscope Endpoint Manager SwEditionon-premise Version >= 9.4.1.0 < 9.4.1.5
MotexLanscope Endpoint Manager SwEditionon-premise Version >= 9.4.2.0 < 9.4.2.6
MotexLanscope Endpoint Manager SwEditionon-premise Version >= 9.4.3.0 < 9.4.3.8
MotexLanscope Endpoint Manager SwEditionon-premise Version >= 9.4.4.0 < 9.4.4.6
MotexLanscope Endpoint Manager SwEditionon-premise Version >= 9.4.5.0 < 9.4.5.4
MotexLanscope Endpoint Manager SwEditionon-premise Version >= 9.4.6.0 < 9.4.6.3
MotexLanscope Endpoint Manager SwEditionon-premise Version >= 9.4.7.0 <= 9.4.7.1

22.10.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability

Schwachstelle

Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packets.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.67% 0.877
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
vultures@jpcert.or.jp 9.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vultures@jpcert.or.jp 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-940 Improper Verification of Source of a Communication Channel

The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.