CVE-2025-8448

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network and the vulnerable products.
CVSS

No CVSS.

Configurations

No configuration.

History

09 Sep 2025, 21:15

Type Values Removed Values Added
Summary
  • (es) CWE-200: Existe una vulnerabilidad de exposición de información confidencial a un actor no autorizado que podría provocar acceso no autorizado a datos de credenciales confidenciales cuando un atacante puede capturar el tráfico SMB local entre un usuario válido dentro de la red BMS y los productos vulnerables.
CVSS v2 : unknown
v3 : 2.3
v2 : unknown
v3 : unknown

20 Aug 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-20 14:15

Updated : 2025-09-09 21:15


NVD link : CVE-2025-8448

Mitre link : CVE-2025-8448

CVE.ORG link : CVE-2025-8448


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor