PT-2025-12330 · Nebula Informatics · Sechard
Published
2025-03-20
·
Updated
2026-06-06
·
CVE-2025-2311
CVSS v3.1
9.0
Critical
| Vector | AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nebula Informatics SecHard versions prior to 3.3.0.20220411
Description
The issue is related to the incorrect use of privileged APIs, cleartext transmission of sensitive information, and insufficiently protected credentials. This allows for authentication bypass, interface manipulation, authentication abuse, and harvesting information via API event monitoring.
Recommendations
For versions prior to 3.3.0.20220411, update to version 3.3.0.20220411 or later to resolve the issue. As a temporary workaround, consider restricting access to privileged APIs and sensitive information to minimize the risk of exploitation. Additionally, ensure that credentials are properly protected and consider disabling API event monitoring until the issue is resolved.
Fix
Cleartext Transmission of Sensitive Information
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sechard