« Volver al listado

CVE-2025-11915

Estado: AplazadaMedia (6.9)—

Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled out for all proxies in front of impacted models by 2025-09-28. Users do not need to take any action.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-11915",
  "cveTags": [
    {
      "tags": [
        "exclusively-hosted-service"
      ],
      "sourceIdentifier": "f45cbf4e-4146-4068-b7e1-655ffc2c548c"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-11915",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-10-22T13:54:15.699505Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "f45cbf4e-4146-4068-b7e1-655ffc2c548c",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 6.9,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "CLEAR",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "LOW",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "LOW",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "f45cbf4e-4146-4068-b7e1-655ffc2c548c",
      "affectedData": [
        {
          "vendor": "Google Cloud",
          "product": "Vertex AI: Partner Models for MaaS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2025-09-26",
              "versionType": "date"
            }
          ],
          "platforms": [
            "https://cloud.google.com/vertex-ai/generative-ai/docs/partner-models/use-partner-models"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Google Cloud",
          "product": "Vertex AI: Open Models for MaaS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2025-09-28",
              "versionType": "date"
            }
          ],
          "platforms": [
            "https://cloud.google.com/vertex-ai/generative-ai/docs/maas/use-open-models"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Google Cloud",
          "product": "Vertex AI: Self-Deployed Models",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2025-09-28",
              "versionType": "date"
            }
          ],
          "platforms": [
            "https://cloud.google.com/vertex-ai/generative-ai/docs/model-garden/self-deployed-models"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-10-22T10:15:31.270",
  "references": [
    {
      "url": "https://cloud.google.com/vertex-ai/generative-ai/docs/security-bulletins#gcp-2025-059",
      "source": "f45cbf4e-4146-4068-b7e1-655ffc2c548c"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f45cbf4e-4146-4068-b7e1-655ffc2c548c",
      "description": [
        {
          "lang": "en",
          "value": "CWE-444"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled out for all proxies in front of impacted models by 2025-09-28. Users do not need to take any action."
    }
  ],
  "lastModified": "2026-06-17T08:31:24.613",
  "sourceIdentifier": "f45cbf4e-4146-4068-b7e1-655ffc2c548c"
}