CVE-2025-3425
Last modified
CVE-2025-3425 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. After analyzing the configuration files, we observed that the server had set the TypeFilterLevel to Full which is dangerous as it can potentially lead to remote code execution using deserialization. This issue affects IntelliSpace Portal: 12 and prior.
Metrics
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:M/U:Green
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-3425?
How severe is CVE-2025-3425?
How do I fix CVE-2025-3425?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-34244Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQ…6.5
- CVE-2025-34245Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQ…6.5
- CVE-2025-34246Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQ…6.5
- CVE-2025-34247Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQ…6.5
- CVE-2025-34248D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a…7.2
- CVE-2025-34249Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-34250Rejected reason: This CVE ID was rejected because it was res…
- CVE-2025-34251Tesla Telematics Control Unit (TCU) firmware prior to v2025.…8.6
- CVE-2025-34252Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-34253D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain …5.4
- CVE-2025-34254D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain …5.3
- CVE-2025-34255D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain …5.3
Are you affected by CVE-2025-3425?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
