CVE-2025-32802
Estado: AplazadaMedia (6.1)—
Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-73, CWE-379
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-32802",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-32802",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-05-28T17:23:10.150529Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-officer@isc.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 4.2,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "security-officer@isc.org",
"affectedData": [
{
"vendor": "ISC",
"product": "Kea",
"versions": [
{
"status": "affected",
"version": "2.4.0",
"versionType": "custom",
"lessThanOrEqual": "2.4.1"
},
{
"status": "affected",
"version": "2.6.0",
"versionType": "custom",
"lessThanOrEqual": "2.6.2"
},
{
"status": "affected",
"version": "2.7.0",
"versionType": "custom",
"lessThanOrEqual": "2.7.8"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-05-28T17:15:23.890",
"references": [
{
"url": "https://kb.isc.org/docs/cve-2025-32802",
"source": "security-officer@isc.org"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-officer@isc.org",
"description": [
{
"lang": "en",
"value": "CWE-73"
},
{
"lang": "en",
"value": "CWE-379"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths.\nThis issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8."
},
{
"lang": "es",
"value": "La configuración de Kea y las directivas de la API permiten sobrescribir archivos arbitrarios, siempre que se otorguen los permisos a Kea. Muchas configuraciones comunes ejecutan Kea como root, dejan los puntos de entrada de la API sin protección por defecto o ubican los sockets de control en rutas no seguras. Este problema afecta a las versiones de Kea 2.4.0 a 2.4.1, 2.6.0 a 2.6.2 y 2.7.0 a 2.7.8."
}
],
"lastModified": "2026-06-17T09:12:35.990",
"sourceIdentifier": "security-officer@isc.org"
}