Login Response Discrepancy in Software from SEL
CVE-2025-48015

3.7LOW

What is CVE-2025-48015?

The SEL software exhibits a login response inconsistency based on the source of the username, leading to potential credential exposure. If a user attempts to log in with a local username, the system may respond differently than when using a central username, creating an opportunity for unauthorized access attempts. This response variance could be exploited by malicious actors to gain insights into valid usernames, thus compromising user accounts. Security measures should be implemented to standardize login responses regardless of username source.

Affected Version(s)

SEL-5056 Software-Defined Network Flow Controller 0 < 2.16.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.