PT-2025-50490 · Senstar · Symphony

Gert Keldermans

+1

·

Published

2025-12-10

·

Updated

2025-12-24

·

CVE-2025-12491

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Senstar Symphony (affected versions not specified)
Description A flaw exists in the implementation of the FetchStoredLicense method in Senstar Symphony, allowing remote attackers to disclose sensitive information without authentication. This information exposure can lead to the disclosure of stored credentials and potential further compromise of the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-12491
ZDI-25-1060

Affected Products

Symphony