CVE-2025-2311CRITICAL 9.0EPSS p5.7%
CVE-2025-2311CVE-2025-2311
Description
Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring.
This issue affects SecHard: before 3.3.0.20220411.
Scoring
| CVSS 3.1 | 9.0 (CRITICAL) |
| Vector | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 0.16% probability of exploitation · percentile 5.7% · 2026-06-18T12:00:27Z |
| Published | 2025-03-20 |
| Last modified | 2026-06-06 |
Underlying weaknesses· 3
References
3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Cleartext Transmission of Sensitive Informationcwe-319 | 0% | live |
| Weakness | Insufficiently Protected Credentialscwe-522 | 0% | live |
| Weakness | Incorrect Use of Privileged APIscwe-648 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.