« Volver al listado

CVE-2025-26698

Estado: AplazadaBaja (2.7)—

Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downloaded to the system where using the product.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-26698",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-26698",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-26T14:46:43.527797Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "vultures@jpcert.or.jp",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 2.7,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "J’s Communication Co., Ltd.",
          "product": "RevoWorks SCVX",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.234 and earlier 4 series versions"
            },
            {
              "status": "affected",
              "version": "5.0.7 and earlier 5 series versions"
            }
          ]
        },
        {
          "vendor": "J’s Communication Co., Ltd.",
          "product": "RevoWorks Browser",
          "versions": [
            {
              "status": "affected",
              "version": "2.2.100 and earlier 2 series versions"
            },
            {
              "status": "affected",
              "version": "3.0.1 and earlier 3 series versions"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-02-26T13:15:41.983",
  "references": [
    {
      "url": "https://jscom.jp/news-20250217/",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN91300609/",
      "source": "vultures@jpcert.or.jp"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vultures@jpcert.or.jp",
      "description": [
        {
          "lang": "en",
          "value": "CWE-669"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downloaded to the system where using the product."
    },
    {
      "lang": "es",
      "value": "Existe un problema de transferencia incorrecta de recursos entre esferas en RevoWorks SCVX y RevoWorks Browser. Si se explota esta vulnerabilidad, se pueden descargar archivos maliciosos en el sistema en el que se utiliza el producto."
    }
  ],
  "lastModified": "2026-06-17T09:02:18.807",
  "sourceIdentifier": "vultures@jpcert.or.jp"
}