« Volver al listado

CVE-2025-41710

Estado: Pendiente de análisisMedia (6.5)—

An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-41710",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-41710",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-10T15:57:59.951313Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "Janitza",
          "product": "UMG 96RM-E 24V(5222063)",
          "versions": [
            {
              "status": "affected",
              "version": "0.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Janitza",
          "product": "UMG 96RM-E 230V(5222062)",
          "versions": [
            {
              "status": "affected",
              "version": "0.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Weidmueller",
          "product": "ENERGY METER 750-230 (2540910000)",
          "versions": [
            {
              "status": "affected",
              "version": "0.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Weidmueller",
          "product": "ENERGY METER 750-24 (2540900000)",
          "versions": [
            {
              "status": "affected",
              "version": "0.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-10T18:17:56.187",
  "references": [
    {
      "url": "https://certvde.com/en/advisories/VDE-2025-079/",
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://certvde.com/en/advisories/VDE-2025-096/",
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://janitza.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-079.json",
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-096.json",
      "source": "info@cert.vde.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write privileges."
    },
    {
      "lang": "es",
      "value": "Un atacante remoto no autenticado puede usar credenciales codificadas para obtener acceso al servidor FTP previamente activado con privilegios limitados de lectura y escritura."
    }
  ],
  "lastModified": "2026-06-17T09:23:01.020",
  "sourceIdentifier": "info@cert.vde.com"
}