{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-4527","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2025-05-10T05:29:57.658Z","datePublished":"2025-05-11T02:00:06.268Z","dateUpdated":"2025-05-12T14:37:50.244Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2025-05-11T02:00:06.268Z"},"title":"Dígitro NGC Explorer Password Transmission client-side enforcement of server-side security","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-602","lang":"en","description":"Client-Side Enforcement of Server-Side Security"}]}],"affected":[{"vendor":"Dígitro","product":"NGC Explorer","versions":[{"version":"3.44.15","status":"affected"}],"modules":["Password Transmission Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability has been found in Dígitro NGC Explorer 3.44.15 and classified as problematic. This vulnerability affects unknown code of the component Password Transmission Handler. The manipulation leads to client-side enforcement of server-side security. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way."},{"lang":"de","value":"In Dígitro NGC Explorer 3.44.15 wurde eine problematische Schwachstelle gefunden. Betroffen ist eine unbekannte Verarbeitung der Komponente Password Transmission Handler. Durch Manipulieren mit unbekannten Daten kann eine client-side enforcement of server-side security-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Die Komplexität eines Angriffs ist eher hoch. Das Ausnutzen gilt als schwierig."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":6.3,"vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":3.7,"vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":3.7,"vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":2.6,"vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N"}}],"timeline":[{"time":"2025-05-10T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2025-05-10T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2025-05-10T07:35:07.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"j369 (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.308272","name":"VDB-308272 | Dígitro NGC Explorer Password Transmission client-side enforcement of server-side security","tags":["vdb-entry"]},{"url":"https://vuldb.com/?ctiid.308272","name":"VDB-308272 | CTI Indicators (IOB, IOC)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.565308","name":"Submit #565308 | Dígitro NGC Explorer 3.44.15 Improper client-side encryption implementation","tags":["third-party-advisory"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-05-12T14:37:44.613444Z","id":"CVE-2025-4527","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-05-12T14:37:50.244Z"}}]}}