PT-2025-12330 · Nebula Informatics · Sechard

Published

2025-03-20

·

Updated

2026-06-06

·

CVE-2025-2311

CVSS v3.1

9.0

Critical

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nebula Informatics SecHard versions prior to 3.3.0.20220411
Description The issue is related to the incorrect use of privileged APIs, cleartext transmission of sensitive information, and insufficiently protected credentials. This allows for authentication bypass, interface manipulation, authentication abuse, and harvesting information via API event monitoring.
Recommendations For versions prior to 3.3.0.20220411, update to version 3.3.0.20220411 or later to resolve the issue. As a temporary workaround, consider restricting access to privileged APIs and sensitive information to minimize the risk of exploitation. Additionally, ensure that credentials are properly protected and consider disabling API event monitoring until the issue is resolved.

Fix

Cleartext Transmission of Sensitive Information

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-2311

Affected Products

Sechard