← volver
CVE-2025-3424

3.2.1 Arbitrary File Read in insecure .NET Remoting TCP Channel

CVSS 7.7 HIGHEPSS 0.2%CWE-22
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.7EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
07 abr 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the "Object Marshalling" technique, which allows an attacker to read internal files without any authentication. This is possible by crafting specific .NET Remoting URLs derived from information enumerated in the client-side configuration files. This issue affects IntelliSpace Portal: 12 and prior.
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:P/AU:Y/R:U/V:C/RE:M/U:Green

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →