CVE-2025-1882
CVE-2025-1882
Título es
CVE-2025-1882
Lun, 03/03/2025 – 21:15
Tipo
CWE-284
Gravedad v2.0
4.30
Gravedad 2.0 Txt
MEDIUM
Título en
CVE-2025-1882
Descripción en
A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality of the component Device Setting Handler. The manipulation leads to improper access control for register interface. The attack needs to be done within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.
03/03/2025
03/03/2025
Vector CVSS:4.0
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vector CVSS:3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Vector CVSS:2.0
AV:A/AC:H/Au:N/C:P/I:P/A:P
Gravedad 4.0
2.30
Gravedad 4.0 txt
LOW
Gravedad 3.1 (CVSS 3.1 Base Score)
5.00
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://github.com/geo-chen/i-Drive
https://vuldb.com/?ctiid_298196=
https://vuldb.com/?id_298196=
https://vuldb.com/?submit_510955=
Enviar en el boletín
Off