CVE-2025-31362
Estado: AplazadaBaja (3.7)—
Use of hard-coded cryptographic key issue exists in BizRobo! all versions. Credentials inside robot files may be obtained if the encryption key is available. The vendor provides the workaround information and recommends to apply it to the deployment environment.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 3.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.24%
- Percentil entre todas las CVEs puntuadas: 14
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-321
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-31362",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-31362",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-04-11T14:36:14.079306Z"
}
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "vultures@jpcert.or.jp",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 3.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "OPEN, Inc.",
"product": "BizRobo!",
"versions": [
{
"status": "affected",
"version": "all versions"
}
]
}
]
}
],
"published": "2025-04-11T10:15:16.413",
"references": [
{
"url": "https://jvn.jp/en/jp/JVN30641875/",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://knowledge.bizrobo.com/hc/ja/articles/360029772271",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://knowledge.bizrobo.com/hc/ja/articles/39951710517145",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://knowledge.bizrobo.com/hc/ja/articles/39952052043289",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://knowledge.bizrobo.com/hc/ja/articles/39953373809305",
"source": "vultures@jpcert.or.jp"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "vultures@jpcert.or.jp",
"description": [
{
"lang": "en",
"value": "CWE-321"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Use of hard-coded cryptographic key issue exists in BizRobo! all versions. Credentials inside robot files may be obtained if the encryption key is available.\r\nThe vendor provides the workaround information and recommends to apply it to the deployment environment."
},
{
"lang": "es",
"value": "Existe un problema con el uso de claves criptográficas codificadas en todas las versiones de BizRobo!. Las credenciales dentro de los archivos robot se pueden obtener si la clave de cifrado está disponible. El proveedor proporciona información sobre el workaround y recomienda aplicarlo al entorno de despliegue."
}
],
"lastModified": "2026-06-17T09:10:17.607",
"sourceIdentifier": "vultures@jpcert.or.jp"
}