Client-Side Security Flaw in Dígitro NGC Explorer Password Transmission Handler
CVE-2025-4527
6.3MEDIUM
What is CVE-2025-4527?
A critical security vulnerability has been identified within the Dígitro NGC Explorer, specifically in version 3.44.15, affecting its Password Transmission Handler component. This vulnerability exposes a serious flaw allowing client-side enforcement of server-side security measures. Attackers may exploit this weakness remotely, posing a significant risk to users as it undermines the integrity of password security mechanisms. Although the attack's complexity is classified as high and exploitation is challenging, the potential for unauthorized access remains a concerning threat. Despite early notifications regarding this issue, the vendor did not provide a response.
Affected Version(s)
NGC Explorer 3.44.15
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
j369 (VulDB User)
