World-Readable Log Files in Kea DHCP Server
CVE-2025-32803
4MEDIUM
What is CVE-2025-32803?
The Kea DHCP Server contains a vulnerability that allows log files and lease files to be accessible by unauthorized users due to improper file permissions. This exposure can lead to the disclosure of sensitive information, potentially compromising the security of network operations. The issue specifically affects Kea versions ranging from 2.4.0 through 2.4.1, as well as versions 2.6.0 through 2.6.2 and 2.7.0 through 2.7.8, necessitating prompt updates to mitigate risks.
Affected Version(s)
Kea 2.4.0 <= 2.4.1
Kea 2.6.0 <= 2.6.2
Kea 2.7.0 <= 2.7.8
References
CVSS V3.1
Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
ISC would like to thank Matthias Gerstner from the SUSE security team for bringing this vulnerability to our attention.