This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker could exploit this vulnerability by accessing certain unauthorized API endpoints leading to detailed error messages as response leading to disclosure of system related information.
Fixes

Solution

Upgrade KYC Solutions to version 1.2


Workaround

No workaround given by the vendor.

History

Wed, 23 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Apr 2025 11:00:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker could exploit this vulnerability by accessing certain unauthorized API endpoints leading to detailed error messages as response leading to disclosure of system related information.
Title Detailed Error Response Vulnerability in Meon KYC solutions
Weaknesses CWE-1295
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2025-04-23T14:44:52.451Z

Reserved: 2025-04-16T12:00:23.726Z

Link: CVE-2025-42604

cve-icon Vulnrichment

Updated: 2025-04-23T14:44:42.517Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-23T11:15:47.190

Modified: 2025-04-23T14:08:13.383

Link: CVE-2025-42604

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.