This vulnerability allows an attacker to access parts of the application that are not protected by any type of access control. The attacker could access this path ‘…/epsilonnet/License/About.aspx’ and obtain information on both the licence and the configuration of the product by knowing which modules are installed.
Advisories

No advisories yet.

Fixes

Solution

Update the product to v3.03.36.0186 or higher.


Workaround

No workaround given by the vendor.

History

Thu, 30 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Grupo Castilla
Grupo Castilla epsilon Rh
Vendors & Products Grupo Castilla
Grupo Castilla epsilon Rh

Wed, 29 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 11:00:00 +0000

Type Values Removed Values Added
Description This vulnerability allows an attacker to access parts of the application that are not protected by any type of access control. The attacker could access this path ‘…/epsilonnet/License/About.aspx’ and obtain information on both the licence and the configuration of the product by knowing which modules are installed.
Title Unprotected access to parts of the application in Epsilon RH by Grupo Castilla
Weaknesses CWE-522
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-10-29T13:33:58.079Z

Reserved: 2025-10-29T10:23:47.181Z

Link: CVE-2025-12461

cve-icon Vulnrichment

Updated: 2025-10-29T13:33:51.891Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-29T11:15:43.883

Modified: 2025-10-30T15:03:13.440

Link: CVE-2025-12461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-30T14:38:43Z