← voltar
CVE-2025-3424

3.2.1 Arbitrary File Read in insecure .NET Remoting TCP Channel

CVSS 7.7 HIGHEPSS 0.2%CWE-22
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 7.7EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
07 abr 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the "Object Marshalling" technique, which allows an attacker to read internal files without any authentication. This is possible by crafting specific .NET Remoting URLs derived from information enumerated in the client-side configuration files. This issue affects IntelliSpace Portal: 12 and prior.
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:P/AU:Y/R:U/V:C/RE:M/U:Green

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →