CVE-2025-51055

HIGH

Vedo Suite <2024.17 - Info Disclosure

Title source: llm
STIX 2.1

Description

Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains clear-text credentials, secret keys, and database information.

Scores

CVSS v3 8.6
EPSS 0.0005
EPSS Percentile 16.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (1)
vedo_suite_project/vedo_suite 2024.17
Published Aug 06, 2025
Tracked Since Feb 18, 2026