« Volver al listado

CVE-2025-41711

Estado: Pendiente de análisisMedia (5.3)—

An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext passwords of accounts with limited access.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-41711",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-41711",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-10T15:57:57.426147Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "Janitza",
          "product": "UMG 96RM-E 24V(5222063)",
          "versions": [
            {
              "status": "affected",
              "version": "0.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Janitza",
          "product": "UMG 96RM-E 230V(5222062)",
          "versions": [
            {
              "status": "affected",
              "version": "0.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Weidmueller",
          "product": "ENERGY METER 750-230 (2540910000)",
          "versions": [
            {
              "status": "affected",
              "version": "0.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Weidmueller",
          "product": "ENERGY METER 750-24 (2540900000)",
          "versions": [
            {
              "status": "affected",
              "version": "0.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-10T18:17:56.380",
  "references": [
    {
      "url": "https://certvde.com/en/advisories/VDE-2025-079/",
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://certvde.com/en/advisories/VDE-2025-096/",
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://janitza.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-079.json",
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-096.json",
      "source": "info@cert.vde.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-327"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext passwords of accounts with limited access."
    },
    {
      "lang": "es",
      "value": "Un atacante remoto no autenticado puede usar imágenes de firmware para extraer hashes de contraseñas y forzar por fuerza bruta contraseñas en texto plano de cuentas con acceso limitado."
    }
  ],
  "lastModified": "2026-06-17T09:23:01.120",
  "sourceIdentifier": "info@cert.vde.com"
}