Description
An unauthenticated remote attacker could use a demo account of the portal to hijack devices that were created in that account by mistake.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14662 | An unauthenticated remote attacker could use a demo account of the portal to hijack devices that were created in that account by mistake. |
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2025-010 |
|
History
Tue, 13 May 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker could use a demo account of the portal to hijack devices that were created in that account by mistake. | |
| Title | SMA: Sunny Portal demo system privilege escalation | |
| Weaknesses | CWE-669 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-05-13T13:11:10.091Z
Reserved: 2025-04-16T11:17:48.305Z
Link: CVE-2025-41645
Updated: 2025-05-13T13:11:06.069Z
Status : Awaiting Analysis
Published: 2025-05-13T09:15:21.190
Modified: 2025-05-13T19:35:18.080
Link: CVE-2025-41645
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD