« Volver al listado

CVE-2025-6943

Estado: AnalizadaMedia (4)—

Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-6943",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-6943",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-02T15:59:37.052875Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "1443cd92-d354-46d2-9290-d812316ca43a",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.8,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 0.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 0.6
      }
    ]
  },
  "affected": [
    {
      "source": "1443cd92-d354-46d2-9290-d812316ca43a",
      "affectedData": [
        {
          "vendor": "Delinea",
          "product": "Secret Server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "11.7"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-07-02T16:15:30.060",
  "references": [
    {
      "url": "https://docs.delinea.com/online-help/secret-server-changelog/secret-server-change-log.htm?cshid=secret-server-changelog#Friday,_November_22,_2024",
      "tags": [
        "Release Notes"
      ],
      "source": "1443cd92-d354-46d2-9290-d812316ca43a"
    },
    {
      "url": "https://docs.delinea.com/online-help/secret-server/release-notes/ss-rn-11-7-000060.htm",
      "tags": [
        "Release Notes"
      ],
      "source": "1443cd92-d354-46d2-9290-d812316ca43a"
    },
    {
      "url": "https://docs.delinea.com/online-help/secret-server/release-notes/ss-rn-11-7-000061.htm",
      "tags": [
        "Release Notes"
      ],
      "source": "1443cd92-d354-46d2-9290-d812316ca43a"
    },
    {
      "url": "https://trust.delinea.com",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "1443cd92-d354-46d2-9290-d812316ca43a"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "1443cd92-d354-46d2-9290-d812316ca43a",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables."
    },
    {
      "lang": "es",
      "value": "La versión 11.7 y anteriores de Secret Server son vulnerables a una vulnerabilidad de creación de informes SQL que permite a un administrador obtener acceso a tablas restringidas."
    }
  ],
  "lastModified": "2026-06-17T10:02:54.970",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:delinea:secret_server:*:*:*:*:on-premises:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "623089B9-9783-4EF5-A7A5-515FF1BB6916",
              "versionEndExcluding": "11.7.000060"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "1443cd92-d354-46d2-9290-d812316ca43a"
}