CVE-2025-3399

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 89
CWE ID 74

Summary

CVE-2025-3399 is a newly disclosed critical vulnerability affecting ESAFENET CDG 5.6.3.154.205_20250114. The issue lies within the unknown functionality of the file /pubinfo/updateNotice.jsp, allowing attackers to execute SQL injection by manipulating the ID argument. This vulnerability can be exploited remotely, with the exploit having been made public. Despite early notification from the disclosers, the vendor has yet to respond.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share