« Volver al listado

CVE-2025-69203

Estado: AnalizadaAlta (8.8)—

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access request system have two related features that when combined by themselves and with an information disclosure vulnerability enable convincing social engineering attacks against administrators. When a device creates an access request, it specifies three fields: `clientId`, `description`, and `permissions`.

Leer descripción completaMostrar menos

The SignalK admin UI displays the `description` field prominently to the administrator when showing pending requests, but the actual `permissions` field (which determines the access level granted) is less visible or displayed separately. This allows an attacker to request `admin` permissions while providing a description that suggests readonly access. The access request handler trusts the `X-Forwarded-For` HTTP header without validation to determine the client's IP address. This header is intended to preserve the original client IP when requests pass through reverse proxies, but when trusted unconditionally, it allows attackers to spoof their IP address. The spoofed IP is displayed to administrators in the access request approval interface, potentially making malicious requests appear to originate from trusted internal network addresses. Since device/source names can be enumerated via the information disclosure vulnerability, an attacker can impersonate a legitimate device or source, craft a convincing description, spoof a trusted internal IP address, and request elevated permissions, creating a highly convincing social engineering scenario that increases the likelihood of administrator approval. Users should upgrade to version 2.19.0 to fix this issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

UI:R requiere interacción del administrador para aprobar la solicitud. Impacto: acceso con permisos elevados (admin) y manipulación de datos del servidor mediante social engineering aprovechando spoofing de IP y descripción engañosa.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-69203",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-69203",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-02T19:02:06.451579Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "SignalK",
          "product": "signalk-server",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.19.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-01-01T19:15:54.067",
  "references": [
    {
      "url": "https://github.com/SignalK/signalk-server/releases/tag/v2.19.0",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/SignalK/signalk-server/security/advisories/GHSA-vfrf-vcj7-wvr8",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-290"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access request system have two related features that when combined by themselves and with an information disclosure vulnerability enable convincing social engineering attacks against administrators. When a device creates an access request, it specifies three fields: `clientId`, `description`, and `permissions`. The SignalK admin UI displays the `description` field prominently to the administrator when showing pending requests, but the actual `permissions` field (which determines the access level granted) is less visible or displayed separately. This allows an attacker to request `admin` permissions while providing a description that suggests readonly access. The access request handler trusts the `X-Forwarded-For` HTTP header without validation to determine the client's IP address. This header is intended to preserve the original client IP when requests pass through reverse proxies, but when trusted unconditionally, it allows attackers to spoof their IP address. The spoofed IP is displayed to administrators in the access request approval interface, potentially making malicious requests appear to originate from trusted internal network addresses. Since device/source names can be enumerated via the information disclosure vulnerability, an attacker can impersonate a legitimate device or source, craft a convincing description, spoof a trusted internal IP address, and request elevated permissions, creating a highly convincing social engineering scenario that increases the likelihood of administrator approval. Users should upgrade to version 2.19.0 to fix this issue."
    },
    {
      "lang": "es",
      "value": "Signal K Server es una aplicación de servidor que se ejecuta en un concentrador central en un barco. Las versiones anteriores a la 2.19.0 del sistema de solicitud de acceso tienen dos características relacionadas que, cuando se combinan por sí mismas y con una vulnerabilidad de revelación de información, permiten ataques convincentes de ingeniería social contra los administradores. Cuando un dispositivo crea una solicitud de acceso, especifica tres campos: 'clientId', 'description' y 'permissions'. La interfaz de usuario de administración de SignalK muestra el campo 'description' de forma destacada al administrador al mostrar las solicitudes pendientes, pero el campo real 'permissions' (que determina el nivel de acceso concedido) es menos visible o se muestra por separado. Esto permite a un atacante solicitar permisos de 'admin' mientras proporciona una descripción que sugiere acceso de solo lectura. El manejador de solicitudes de acceso confía en el encabezado HTTP 'X-Forwarded-For' sin validación para determinar la dirección IP del cliente. Este encabezado está destinado a preservar la IP original del cliente cuando las solicitudes pasan a través de proxies inversos, pero cuando se confía incondicionalmente en él, permite a los atacantes falsificar su dirección IP. La IP falsificada se muestra a los administradores en la interfaz de aprobación de solicitudes de acceso, lo que potencialmente hace que las solicitudes maliciosas parezcan originarse de direcciones de red internas de confianza. Dado que los nombres de dispositivos/fuentes pueden enumerarse a través de la vulnerabilidad de revelación de información, un atacante puede suplantar un dispositivo o fuente legítima, elaborar una descripción convincente, falsificar una dirección IP interna de confianza y solicitar permisos elevados, creando un escenario de ingeniería social altamente convincente que aumenta la probabilidad de aprobación del administrador. Los usuarios deben actualizar a la versión 2.19.0 para solucionar este problema."
    }
  ],
  "lastModified": "2026-10-01T08:10:00.183",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:signalk:signal_k_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "102A9593-CCDC-4532-8201-E67EEFC665E0",
              "versionEndExcluding": "2.19.0"
            },
            {
              "criteria": "cpe:2.3:a:signalk:signal_k_server:2.19.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "67C0C9C4-176E-457B-97BF-56EED79F4D42"
            },
            {
              "criteria": "cpe:2.3:a:signalk:signal_k_server:2.19.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F33D560-D916-45D7-AAF6-63E89BE06805"
            },
            {
              "criteria": "cpe:2.3:a:signalk:signal_k_server:2.19.0:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B544F41-AFE7-454F-BE01-89AC7B954AF5"
            },
            {
              "criteria": "cpe:2.3:a:signalk:signal_k_server:2.19.0:beta4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BCF3D7E0-66FE-47F1-97BA-ABCF769B0D7C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}