CVE-2025-2311
Last modified
CVE-2025-2311 is a critical-severity vulnerability rated 9/10 on the CVSS scale. Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring. This issue affects SecHard: before 3.3.0.20220411.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring. This issue affects SecHard: before 3.3.0.20220411.
Metrics
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-2311?
How severe is CVE-2025-2311?
How do I fix CVE-2025-2311?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-23104An issue was discovered in Samsung Mobile Processor Exynos 2…6.5
- CVE-2025-23105An issue was discovered in Samsung Mobile Processor Exynos 2…7.8
- CVE-2025-23106An issue was discovered in Samsung Mobile Processor Exynos 2…6.5
- CVE-2025-23107An issue was discovered in Samsung Mobile Processor Exynos 1…8.6
- CVE-2025-23108Opening Javascript links in a new tab via long-press in the …4.3
- CVE-2025-23109Long hostnames in URLs could be leveraged to obscure the act…6.5
- CVE-2025-23110An issue was discovered in REDCap 14.9.6. A Reflected cross-…6.1
- CVE-2025-23111An issue was discovered in REDCap 14.9.6. It allows HTML Inj…6.1
- CVE-2025-23112An issue was discovered in REDCap 14.9.6. A stored cross-sit…6.1
- CVE-2025-23113An issue was discovered in REDCap 14.9.6. It has an action=m…8.8
- CVE-2025-23114A vulnerability in Veeam Updater component allows Man-in-the…9
- CVE-2025-23115A Use After Free vulnerability on UniFi Protect Cameras coul…9
Are you affected by CVE-2025-2311?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
