CVE-2025-11602
Last modified
CVE-2025-11602 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The attacker has no control over the information leaked in server responses.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The attacker has no control over the information leaked in server responses.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:X/U:Clear
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-11602?
How severe is CVE-2025-11602?
How do I fix CVE-2025-11602?
Are you affected by CVE-2025-11602?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
