CVE-2025-1880
CVE-2025-1880
Título es
CVE-2025-1880
Lun, 03/03/2025 – 20:15
Tipo
CWE-287
Gravedad v2.0
1.20
Gravedad 2.0 Txt
LOW
Título en
CVE-2025-1880
Descripción en
A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as problematic. Affected is an unknown function of the component Device Pairing. The manipulation leads to authentication bypass by primary weakness. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitability is told to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.
03/03/2025
03/03/2025
Vector CVSS:4.0
CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vector CVSS:3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Vector CVSS:2.0
AV:L/AC:H/Au:N/C:P/I:N/A:N
Gravedad 4.0
1.00
Gravedad 4.0 txt
LOW
Gravedad 3.1 (CVSS 3.1 Base Score)
2.00
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
LOW
Referencias
https://github.com/geo-chen/i-Drive
https://vuldb.com/?ctiid_298194=
https://vuldb.com/?id_298194=
https://vuldb.com/?submit_510951=
Enviar en el boletín
Off