Remote Information Disclosure Vulnerability in ABC Inc. Web Application
CVE-2025-3090
8.2HIGH
What is CVE-2025-3090?
An unauthenticated remote attacker can exploit a flaw in the ABC Inc. web application, allowing them to gain access to sensitive information and potentially cause a denial of service (DoS) by leveraging missing authentication mechanisms for critical functions. This vulnerability highlights the importance of robust authentication protocols to safeguard against unauthorized access and protect user data.
Affected Version(s)
mbCONNECT24 0 < 2.18.0
mymbCONNECT24 0 < 2.18.0
myREX24 0 < 2.18.0
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
