CVE-2025-48464
⚪ Do wiadomości
Wykorzystanie podatności w Sync umożliwia nieautoryzowanym atakującym dostęp do danych konta.
CVSS
4.7
EPSS
0.1%
Exploit
none
Vendor
Opis źródłowy (NVD)
Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync account data such as account credentials and email protection information.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.7 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.1% |
| Opublikowano (NVD) | 2025-10-08 07:15:33 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 13:10:00 UTC |
Referencje
- https://tuxplorer.com/posts/dont-leave-me-outdated/ (5f57b9bf-260d-4433-bf07-b6a79e9bb7d4)
- https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-097/ (5f57b9bf-260d-4433-bf07-b6a79e9bb7d4)