Rapid Response Monitoring My Security Account App utilizes an API that could be exploited by an attacker to modify request data, potentially causing the API to return information about other users.
Fixes

Solution

Rapid Response Monitoring reports that this issue was patched on their end and no action is required by users. For further information, contact https://www.rrms.com/contact-us/  Rapid Response Monitoring.


Workaround

No workaround given by the vendor.

History

Thu, 20 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Feb 2025 19:30:00 +0000

Type Values Removed Values Added
Description Rapid Response Monitoring My Security Account App utilizes an API that could be exploited by an attacker to modify request data, potentially causing the API to return information about other users.
Title Rapid Response Monitoring My Security Account App Authorization Bypass Through User-Controlled Key
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-02-20T20:24:19.657Z

Reserved: 2025-01-08T23:28:47.919Z

Link: CVE-2025-0352

cve-icon Vulnrichment

Updated: 2025-02-20T20:19:53.686Z

cve-icon NVD

Status : Received

Published: 2025-02-20T20:15:46.383

Modified: 2025-02-20T20:15:46.383

Link: CVE-2025-0352

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.