CVE-2025-67223
Last modified
CVE-2025-67223 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls to download sensitive documents containing PII.. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls to download sensitive documents containing PII.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-67223?
How severe is CVE-2025-67223?
How do I fix CVE-2025-67223?
Are you affected by CVE-2025-67223?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
