PT-2025-6792 · Progress · Progress Telerik Report Server

Published

2025-02-12

·

Updated

2025-02-20

·

CVE-2025-0556

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions In Progress Telerik Report Server versions prior to 2025 Q1 (11.0.25.211)
Description The issue concerns the communication of non-sensitive information between the service agent process and app host process in In Progress Telerik Report Server. When using the older .NET Framework implementation, this communication occurs over an unencrypted tunnel. As a result, it can be subjected to local network traffic sniffing.
Recommendations For versions prior to 2025 Q1 (11.0.25.211), update to version 2025 Q1 (11.0.25.211) or later to resolve the issue. As a temporary workaround, consider restricting access to the communication tunnel between the service agent process and app host process to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-0556

Affected Products

Progress Telerik Report Server