« Volver al listado

CVE-2025-46748

Estado: AplazadaBaja (2.7)—

An authenticated user attempting to change their password could do so without using the current password.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-46748",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-46748",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-12T17:39:10.440143Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@selinc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@selinc.com",
      "affectedData": [
        {
          "vendor": "Schweitzer Engineering Laboratories",
          "product": "SEL Blueframe OS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.10.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-05-12T17:15:48.633",
  "references": [
    {
      "url": "https://selinc.com/products/software/latest-software-versions/",
      "source": "security@selinc.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@selinc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-620"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An authenticated user attempting to change their password could do so without using the current password."
    },
    {
      "lang": "es",
      "value": "Un usuario autenticado que intente cambiar su contraseña podría hacerlo sin utilizar la contraseña actual."
    }
  ],
  "lastModified": "2026-06-17T09:26:55.433",
  "sourceIdentifier": "security@selinc.com"
}