PT-2025-26594 · Brain2 · Brain2
Published
2025-06-23
·
Updated
2025-06-28
·
CVE-2025-6513
CVSS v3.1
9.3
Critical
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
BRAIN2 versions 0.0 through 3.05
Description:
The configuration file for database access of the BRAIN2 application is not sufficiently secured, allowing standard Windows users to access and decrypt it. This issue is related to the storage of passwords in configuration files.
Recommendations:
For BRAIN2 versions 0.0 through 3.05, consider restricting access to the configuration file for database access to prevent unauthorized decryption. As a temporary workaround, limit the privileges of standard Windows users to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brain2