CVE-2025-3895

Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with a queryable value. It allows an unauthenticated attacker who know user login names to brute force these tokens and change account passwords (including these belonging to administrators).  Version 5.20 of MegaBIP fixes this issue.
CVSS

No CVSS.

Configurations

No configuration.

History

23 May 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-23 11:15

Updated : 2025-05-23 15:54


NVD link : CVE-2025-3895

Mitre link : CVE-2025-3895

CVE.ORG link : CVE-2025-3895


JSON object : View

Products Affected

No product.

CWE
CWE-334

Small Space of Random Values