World-Readable Log Files in Kea DHCP Server
CVE-2025-32803

4MEDIUM

Key Information:

Vendor

Isc

Status
Vendor
CVE Published:
28 May 2025

Badges

👾 Exploit Exists

What is CVE-2025-32803?

The Kea DHCP Server contains a vulnerability that allows log files and lease files to be accessible by unauthorized users due to improper file permissions. This exposure can lead to the disclosure of sensitive information, potentially compromising the security of network operations. The issue specifically affects Kea versions ranging from 2.4.0 through 2.4.1, as well as versions 2.6.0 through 2.6.2 and 2.7.0 through 2.7.8, necessitating prompt updates to mitigate risks.

Affected Version(s)

Kea 2.4.0 <= 2.4.1

Kea 2.6.0 <= 2.6.2

Kea 2.7.0 <= 2.7.8

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

ISC would like to thank Matthias Gerstner from the SUSE security team for bringing this vulnerability to our attention.
.
CVE-2025-32803 : World-Readable Log Files in Kea DHCP Server