Weak File Name Generation in vsDesk Application
CVE-2025-14602
5.3MEDIUM
What is CVE-2025-14602?
The vsDesk application exhibits a vulnerability in its file name generation process, which relies on a weak and predictable mechanism based on request timestamps. This flaw enables remote attackers to guess or brute-force the generated filenames within a minimal timeframe. Successful exploitation allows unauthorized access to uploaded files, facilitating potential follow-up attacks. It is crucial for users of affected versions to apply the available patch to mitigate this risk.
Affected Version(s)
vsDesk 11.06.02
vsDesk 14.0101
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
The vulnerability was discovered by Kirill Nikolaev from Kaspersky (https://kaspersky.com)
