« Volver al listado

CVE-2025-63212

Estado: AnalizadaMedia (6.5)—

GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) in the publicly accessible log file located at /log/Flexiva%20LX.log. An unauthenticated attacker can retrieve valid session IDs and hijack sessions without providing any credentials. This attack requires the legitimate user (admin) to have previously closed the browser window without logging out.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-63212",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-63212",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-11-20T21:01:41.771788Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-11-19T20:15:53.380",
  "references": [
    {
      "url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63212%20_GatesAir%20Flexiva-LX%20Series%20_%20Session%20Hijacking",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.gatesair.com/",
      "tags": [
        "Product"
      ],
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) in the publicly accessible log file located at /log/Flexiva%20LX.log. An unauthenticated attacker can retrieve valid session IDs and hijack sessions without providing any credentials. This attack requires the legitimate user (admin) to have previously closed the browser window without logging out."
    }
  ],
  "lastModified": "2026-06-17T09:52:56.930",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gatesair:flexiva_lx100_firmware:1.0.13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAE101C6-1663-4A58-B9A7-41BAFD0B2BA1"
            },
            {
              "criteria": "cpe:2.3:o:gatesair:flexiva_lx100_firmware:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F5CE624-254C-472E-8D1D-1C3463281CA0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gatesair:flexiva_lx100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4F1D8D39-E16E-440C-AC90-8060CB2C0EB4"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gatesair:flexiva_lx300_firmware:1.0.13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D1F6D30-F5D0-4D5A-890D-F9BBCBBB3C45"
            },
            {
              "criteria": "cpe:2.3:o:gatesair:flexiva_lx300_firmware:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A53C617-AA10-46A9-B596-3CBC5D4760D5"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gatesair:flexiva_lx300:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9A57C780-A6FD-4C47-A7CC-3F5F09B92B16"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gatesair:flexiva_lx600_firmware:1.0.13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "67C103A0-68B1-449B-95AA-12B8467A6588"
            },
            {
              "criteria": "cpe:2.3:o:gatesair:flexiva_lx600_firmware:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C78DD920-FF73-4575-AE89-AF6608857C25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gatesair:flexiva_lx600:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4EAAF4DB-9F0D-4401-9560-1C463274EB9C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gatesair:flexiva_lx1000_firmware:1.0.13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EEA61DCA-EAAC-4C60-9070-8AAFF7F2B821"
            },
            {
              "criteria": "cpe:2.3:o:gatesair:flexiva_lx1000_firmware:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B168C928-7586-4AB9-95FB-5D759350AD6F"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gatesair:flexiva_lx1000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7882D4C9-E3F8-40B9-BDFC-0216066E7907"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}