From 3d6bd68872007eb1ea1092ca40735ca2b20abcfe Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 5 May 2025 12:32:10 +0000 Subject: [PATCH] Publish Advisories GHSA-h7mx-548v-cr9r GHSA-33cx-2vvq-mf52 GHSA-hpr7-5g9m-r2j8 --- .../GHSA-h7mx-548v-cr9r.json | 6 +- .../GHSA-33cx-2vvq-mf52.json | 36 ++++++++++++ .../GHSA-hpr7-5g9m-r2j8.json | 56 +++++++++++++++++++ 3 files changed, 97 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-33cx-2vvq-mf52/GHSA-33cx-2vvq-mf52.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hpr7-5g9m-r2j8/GHSA-hpr7-5g9m-r2j8.json diff --git a/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json b/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json index cba6eafdced..82c09c7a624 100644 --- a/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json +++ b/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h7mx-548v-cr9r", - "modified": "2025-05-05T09:31:09Z", + "modified": "2025-05-05T12:30:33Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-3155" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4451" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4455" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-3155" diff --git a/advisories/unreviewed/2025/05/GHSA-33cx-2vvq-mf52/GHSA-33cx-2vvq-mf52.json b/advisories/unreviewed/2025/05/GHSA-33cx-2vvq-mf52/GHSA-33cx-2vvq-mf52.json new file mode 100644 index 00000000000..ce42106cadc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-33cx-2vvq-mf52/GHSA-33cx-2vvq-mf52.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33cx-2vvq-mf52", + "modified": "2025-05-05T12:30:34Z", + "published": "2025-05-05T12:30:34Z", + "aliases": [ + "CVE-2025-2545" + ], + "details": "Vulnerability in Best Practical Solutions, LLC's Request Tracker v5.0.7, where the Triple DES (3DES) cryptographic algorithm is used within SMIME code to encrypt S/MIME emails. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2545" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/cryptographic-algorithm-not-recommended-request-tracker-best-practical" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hpr7-5g9m-r2j8/GHSA-hpr7-5g9m-r2j8.json b/advisories/unreviewed/2025/05/GHSA-hpr7-5g9m-r2j8/GHSA-hpr7-5g9m-r2j8.json new file mode 100644 index 00000000000..1b09d321653 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hpr7-5g9m-r2j8/GHSA-hpr7-5g9m-r2j8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpr7-5g9m-r2j8", + "modified": "2025-05-05T12:30:34Z", + "published": "2025-05-05T12:30:34Z", + "aliases": [ + "CVE-2025-4272" + ], + "details": "A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is some unknown functionality in the library C:\\Program Files\\OEM\\MECHREVO Control Center\\UniwillService\\MyControlCenter\\csCAPI.dll of the component GCUService. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4272" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1VKhLyW0oglACkt-5PgTtN9oRB2jMczeh/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307376" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307376" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.563468" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/ba1ma0-an29k/nnxoap/bhd5ckqugggmpttp?singleDoc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T11:15:45Z" + } +} \ No newline at end of file