Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted access via the network. The vulnerability is fixed in Version 1.5.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 27 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 27 May 2025 08:00:00 +0000

Type Values Removed Values Added
Description Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted access via the network. The vulnerability is fixed in Version 1.5.
Title Missing Authentication & Authorization in Web-API allows adversary unrestricted access
Weaknesses CWE-306
CWE-862
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y/R:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2025-05-27T13:59:38.622Z

Reserved: 2025-03-17T12:57:47.910Z

Link: CVE-2025-2407

cve-icon Vulnrichment

Updated: 2025-05-27T13:59:35.723Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-27T08:15:19.610

Modified: 2025-05-28T15:01:30.720

Link: CVE-2025-2407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.