---
cve: "CVE-2025-8305"
severity: "MEDIUM"
cvss: 6.5
epss: "0.1%"
vendor: "checkpoint"
kev: false
exploited: false
published: "2025-12-22 08:15:46"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-23T03:39:43+02:00"
---

# CVE-2025-8305

> 6.5 MEDIUM

## Beschreibung

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in Identity Agent for Terminal Services debug files.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://support.checkpoint.com/results/sk/sk184264>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-8305) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
