CVE-2025-22493
Estado: AplazadaMedia (5.6)—
Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session cookie being transmitted over unencrypted HTTP connections. This security issue has been resolved in the latest version of FRS v1.5.100.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
- Puntuación base: 5.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.11%
- Percentil entre todas las CVEs puntuadas: 1
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-319
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-22493",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-22493",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-03-05T14:50:30.680284Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "CybersecurityCOE@eaton.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.6,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 4.7,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "CybersecurityCOE@eaton.com",
"affectedData": [
{
"vendor": "Eaton",
"product": "Foreseer Reporting Software (FRS)",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.5.100",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-03-05T09:15:10.443",
"references": [
{
"url": "https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2024-1009.pdf",
"source": "CybersecurityCOE@eaton.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "CybersecurityCOE@eaton.com",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session cookie being transmitted over unencrypted HTTP connections. This security issue has been resolved in the latest version of FRS v1.5.100."
},
{
"lang": "es",
"value": "No se ha establecido el indicador de seguridad y SameSIte se ha establecido en Lax en el software de informes Foreseer (FRS). La ausencia de este indicador de seguridad podría provocar que la cookie de sesión se transmita a través de conexiones HTTP no cifradas. Este problema de seguridad se ha resuelto en la última versión de FRS v1.5.100."
}
],
"lastModified": "2026-06-17T08:47:45.003",
"sourceIdentifier": "CybersecurityCOE@eaton.com"
}