← volver
CVE-2025-6685

ATEN eco DC Missing Authorization Privilege Escalation Vulnerability

CVSS 8.8 HIGHEPSS 0.7%CWE-862
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.8EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
02 sep 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
ATEN eco DC Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of ATEN eco DC. Authentication is required to exploit this vulnerability. The specific flaw exists within the web-based interface. The issue results from the lack of validating the assigned user role when handling requests. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-26647.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
ATEN · eco DC

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →