CVE-2025-8853
2100 Technology|Official Document Management System - Authentication Bypass
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.3EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
11 ago 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
2100 Technology · Official Document Management System¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →