CVE-2025-24521
CVE-2025-24521
Título es
CVE-2025-24521
Mié, 05/03/2025 – 16:15
Tipo
CWE-611
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-24521
Descripción en
External XML entity injection allows arbitrary download of files. The
score without least privilege principle violation is as calculated
below. In combination with other issues it may facilitate further
compromise of the device. Remediation in Version 6.8.0, release date:
01-Mar-25.
05/03/2025
05/03/2025
Vector CVSS:4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Gravedad 4.0
6.90
Gravedad 4.0 txt
MEDIUM
Gravedad 3.1 (CVSS 3.1 Base Score)
4.90
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://support.ixiacom.com/
https://support.ixiacom.com/support-overview/product-support/downloads-updates
https://www.cisa.gov/news-events/ics-advisories/icsa-25-063-02
https://www.keysight.com/us/en/contact.html
Enviar en el boletín
Off
