CVE-2025-68273
⚪ Do wiadomości
Nieautoryzowany wyciek informacji w Signal K Server umożliwia dostęp do wrażliwych danych systemowych.
CVSS
5.3
EPSS
0.8%
Exploit
poc
Vendor
signalk
Opis źródłowy (NVD)
Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks. Version 2.19.0 patches the issue.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.8% |
| Opublikowano (NVD) | 2026-01-01 19:15:53 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-01 08:10:00 UTC |
Referencje
- https://github.com/SignalK/signalk-server/releases/tag/v2.19.0 ([email protected]) [Release Notes]
- https://github.com/SignalK/signalk-server/security/advisories/GHSA-fpf5-w967-rr2m ([email protected]) [Exploit, Vendor Advisory]