CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network and the vulnerable products.
Metrics
Affected Vendors & Products
References
History
Wed, 20 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 20 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network and the vulnerable products. | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: schneider
Published: 2025-08-20T13:58:53.818Z
Updated: 2025-08-20T15:51:53.932Z
Reserved: 2025-07-31T21:02:43.599Z
Link: CVE-2025-8448

Updated: 2025-08-20T15:51:50.967Z

Status : Awaiting Analysis
Published: 2025-08-20T14:15:48.667
Modified: 2025-08-20T14:39:07.860
Link: CVE-2025-8448

No data.