CVE-2025-2311

CRITICAL

SecHard <3.3.0.20220411 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring.This issue affects SecHard: before 3.3.0.20220411.

Scores

CVSS v3 9.0
EPSS 0.0001
EPSS Percentile 0.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-319 CWE-522 CWE-648
Status published
Products (1)
Sechard Information Technologies/SecHard < 3.3.0.20220411
Published Mar 20, 2025
Tracked Since Feb 18, 2026