Authentication bypass by spoofing issue exists in FileMegane versions above 1.0.0.0 prior to 3.4.0.0, which may lead to user impersonation. If exploited, restricted file contents may be accessed.
History

Tue, 18 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Feb 2025 00:15:00 +0000

Type Values Removed Values Added
Description Authentication bypass by spoofing issue exists in FileMegane versions above 1.0.0.0 prior to 3.4.0.0, which may lead to user impersonation. If exploited, restricted file contents may be accessed.
Weaknesses CWE-290
References
Metrics cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2025-02-18T15:42:32.539Z

Reserved: 2025-02-03T08:50:27.677Z

Link: CVE-2025-25055

cve-icon Vulnrichment

Updated: 2025-02-18T15:42:20.588Z

cve-icon NVD

Status : Received

Published: 2025-02-18T00:15:21.277

Modified: 2025-02-18T00:15:21.277

Link: CVE-2025-25055

cve-icon Redhat

No data.