IM
IronMonkey Threat Research

CVE-2025-2002 MEDIUM

Published: 2025-03-12 | Last Modified: 2026-04-15 | Status: Deferred

Description

CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, and the device is placed in debug mode by an administrative user and the debug files are exported from the device.

Additional Descriptions (1)

CWE-532: Existe una vulnerabilidad de inserción de información confidencial en archivos de registro que podría provocar la divulgación de las credenciales del servidor FTP cuando se implementa el servidor FTP y un usuario administrativo coloca el dispositivo en modo de depuración y los archivos de depuración se exportan desde el dispositivo.

CVSS Metrics

Base Score: 6.0 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactHIGH
Integrity ImpactNONE
Availability ImpactNONE

Source: [email protected]

Type: Secondary

Exploitability Score: 1.5

Impact Score: 4.0

Base Score: 4.0 (MEDIUM)

CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack VectorLOCAL
Attack ComplexityLOW
Attack RequirementsPRESENT
Privileges RequiredHIGH
User InteractionNONE
Vulnerability ConfidentialityNONE
Vulnerability IntegrityNONE
Vulnerability AvailabilityNONE
Subsequent ConfidentialityHIGH
Subsequent IntegrityNONE
Subsequent AvailabilityNONE

Source: [email protected]

Type: Secondary

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-532
Notification
Message here