Incorrect string encoding vulnerability in NASK - PIB BotSense allows injection of an additional field separator character or value in the content of some fields of the generated event. A field with additional field separator characters or values can be included in the "extraData" field.This issue affects BotSense in versions before 2.8.0.
History

Mon, 17 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Description Incorrect string encoding vulnerability in NASK - PIB BotSense allows injection of an additional field separator character or value in the content of some fields of the generated event. A field with additional field separator characters or values can be included in the "extraData" field.This issue affects BotSense in versions before 2.8.0.
Title Logs manipulation in BotSense
Weaknesses CWE-142
CWE-143
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2025-03-17T15:17:24.213Z

Reserved: 2025-02-28T07:57:08.188Z

Link: CVE-2025-1774

cve-icon Vulnrichment

Updated: 2025-03-17T15:17:19.711Z

cve-icon NVD

Status : Received

Published: 2025-03-17T15:15:43.523

Modified: 2025-03-17T15:15:43.523

Link: CVE-2025-1774

cve-icon Redhat

No data.