« Volver al listado

CVE-2025-57796

Estado: AnalizadaMedia (6.8)—

Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sensitive data, including user passwords and system configurations. This approach allows stored values to be decrypted offline if the encrypted data are obtained.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-57796",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-57796",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-28T18:10:56.263409Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "mandiant-cve@google.com",
      "affectedData": [
        {
          "vendor": "Explorance",
          "product": "Blue",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "8.14.12",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-01-28T18:16:49.940",
  "references": [
    {
      "url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0005.md",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "mandiant-cve@google.com"
    },
    {
      "url": "https://online-help.explorance.com/blue/articles/security-advisories-(january-2026)",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "mandiant-cve@google.com"
    },
    {
      "url": "https://online-help.explorance.com/blue/articles/security-advisory:-cve-2025-57796",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "mandiant-cve@google.com"
    },
    {
      "url": "https://www.explorance.com/products/blue",
      "tags": [
        "Product"
      ],
      "source": "mandiant-cve@google.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "mandiant-cve@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-257"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sensitive data, including user passwords and system configurations. This approach allows stored values to be decrypted offline if the encrypted data are obtained."
    },
    {
      "lang": "es",
      "value": "Las versiones de Explorance Blue anteriores a la 8.14.12 utilizan cifrado simétrico reversible con una clave estática codificada de forma rígida para proteger datos sensibles, incluyendo contraseñas de usuario y configuraciones del sistema. Este enfoque permite que los valores almacenados sean descifrados sin conexión si se obtienen los datos cifrados."
    }
  ],
  "lastModified": "2026-06-17T09:43:27.100",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:explorance:blue:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4DE2E7BA-5E00-494C-9737-45F26E3384F2",
              "versionEndExcluding": "8.14.12"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "mandiant-cve@google.com"
}