← Volver a CVEs
CVE-2025-67223
HIGH7.5
Descripcion
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls to download sensitive documents containing PII.
Detalles CVE
Puntuacion CVSS v3.17.5
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado4/28/2026
Ultima modificacion4/28/2026
Fuentenvd
Avistamientos honeypot0
Debilidades (CWE)
CWE-377CWE-532
Referencias
https://docs.arandasoft.com/at-v8-release-notes/en/pages/release_pdf/file_server.html(cve@mitre.org)
https://github.com/brandonperezlara/CVE-2025-67223(cve@mitre.org)
https://github.com/brandonperezlara/CVE-2025-67223(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.