CRITICAL🇵🇱 Wersja polska

CVE-2025-2311

CVSS 9.0v3.1pub. 2025-03-20upd. 2026-06-06

Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring. This issue affects SecHard: before 3.3.0.20220411.

🤖 AI Analysis
How it works

The SecHard product improperly uses privileged APIs (CWE-648), which allows an attacker to manipulate interfaces and abuse authentication mechanisms. Additionally, sensitive data, including credentials, are transmitted in unencrypted form (CWE-319), which enables their interception on the local network. Insufficient protection of stored and transmitted authentication credentials (CWE-522) further facilitates their acquisition through API event monitoring.

Impact

An attacker with access to the local network and basic privileges can bypass authentication mechanisms, manipulate system interfaces, and obtain credentials of other users — which can ultimately lead to full system takeover (violation of confidentiality, integrity, and availability).

Mitigation & patch

Update SecHard to version 3.3.0.20220411 or later. Detailed information is available in the manufacturer's references and in bulletin TR-25-0074 published by USOM.

Who is affected

SecHard (Sechard Information Technologies) in all versions prior to 3.3.0.20220411.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References