CVE-2025-2306
Estado: AplazadaMedia (5.9)—
An Improper Access Control vulnerability was identified in the file download functionality. This vulnerability allows users to download sensitive documents without authentication, if the URL is known.
The attack requires the attacker to know the documents UUIDv4.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.45%
- Percentil entre todas las CVEs puntuadas: 37
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
CWE
- CWE-284
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-2306",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-2306",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-05-16T13:02:34.088925Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "a341c0d1-ebf7-493f-a84e-38cf86618674",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "a341c0d1-ebf7-493f-a84e-38cf86618674",
"affectedData": [
{
"vendor": "SYNCPILOT",
"product": "LIVE CONTRACT",
"versions": [
{
"status": "affected",
"version": "3",
"lessThan": "5.4.12",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.5",
"lessThan": "5.5.4",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.6",
"lessThan": "5.6.3",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-05-16T13:15:52.307",
"references": [
{
"url": "https://www.cirosec.de/sa/sa-2025-004",
"source": "a341c0d1-ebf7-493f-a84e-38cf86618674"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "a341c0d1-ebf7-493f-a84e-38cf86618674",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An Improper Access Control vulnerability was\nidentified in the file download functionality. This vulnerability allows users\nto download sensitive documents without authentication, if the URL is known.\n\n\n\nThe attack\nrequires the attacker to know the documents UUIDv4."
},
{
"lang": "es",
"value": "Se identificó una vulnerabilidad de control de acceso inadecuado en la funcionalidad de descarga de archivos. Esta vulnerabilidad permite a los usuarios descargar documentos confidenciales sin autenticación si se conoce la URL. El ataque requiere que el atacante conozca el UUIDv4 de los documentos."
}
],
"lastModified": "2026-06-17T09:06:43.617",
"sourceIdentifier": "a341c0d1-ebf7-493f-a84e-38cf86618674"
}