« Volver al listado

RBI

RBI Restaurant Brands International Assistant: vulnerabilidades y CVE

RBI Restaurant Brands International Assistant tiene 10 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses10
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-62651Media (5.8)0.39%—17 oct 2025
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating interface.
CVE-2025-62650Crítica (9.9)0.50%—17 oct 2025
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostic screen.
CVE-2025-62649Media (5.8)0.51%—17 oct 2025
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for submission of equipment orders.
CVE-2025-62647Media (5.8)0.38%—17 oct 2025
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to call an API to return a signed AWS upload URL, for any store's path.
CVE-2025-62646Alta (7.7)0.54%—17 oct 2025
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.
CVE-2025-62645Crítica (9.9)0.72%—17 oct 2025
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL…
CVE-2025-62644Alta (7.7)0.46%—17 oct 2025
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users.
CVE-2025-62643Alta (8.6)0.32%—17 oct 2025
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages.
CVE-2025-62642Alta (8.6)0.49%—17 oct 2025
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, allowing a remote unauthenticated attacker to…
CVE-2025-62648Media (5.8)0.39%—17 oct 2025
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application3
  2. T1210 Exploitation of Remote Services3
  3. T1212 Exploitation for Credential Access2
  4. T1005 Data from Local System1
  5. T1078 Valid Accounts1
  6. T1098.003 Additional Cloud Roles1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.