Intelligence View
⚡ tsecurity.de Intelligence
CVE-2025-64323 | kgateway up to 2.0.4/2.1.0-rc2 Configuration Data authorization (ID 10651 / EUVD-2025-37852)
A vulnerability was found in kgateway up to 2.0.4/2.1.0-rc2 and classified as problematic. This affects an unknown function of the component Configuration Data…
A vulnerability was found in kgateway up to 2.0.4/2.1.0-rc2 and classified as problematic. This affects an unknown function of the component Configuration Data Handler. The manipulation results in missing authorization.
This vulnerability is reported as CVE-2025-64323. The attacker must have access to the local network to execute the attack. No exploit exists.
It is suggested to upgrade the affected component.
This vulnerability is reported as CVE-2025-64323. The attacker must have access to the local network to execute the attack. No exploit exists.
It is suggested to upgrade the affected component.
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
CVSS 5.3CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Impact: 3.6 | Exploitability: 1.62
AVA
Angrenzendes Netzwerk (WLAN / LAN)
Erfordert Zugriff auf dasselbe Subnetz oder Funknetz.
ACH
Hoch (High)
Erfordert Vorwissen, spezifische Zeitfenster oder unzuverlässige Race Conditions.
PRN
Keine (Unauthenticated)
Vollständig unauthentifiziert ohne Benutzerkonto exploitbar.
UIN
Keine (Zero-Click)
Autonom ohne menschliches Zutun ausführbar (Zero-Click Exploitation).
SU
Unverändert (Scope Unchanged)
Auswirkungen verbleiben isoliert in der angreifbaren Anwendungskomponente.
CH
Hoch (Totaler Abfluss)
Vollständiger Zugriff auf alle sensiblen Datenbank- und Speicherinhalte.
IN
Keine
Teilweise oder keine Manipulation.
AN
Keine
Teilweise oder keine Beeinträchtigung.
CISA-SSVC-Triage (vulnrichment)CVE-2025-64323
Exploitation: none (Keine bekannte Ausnutzung)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2025-11-07T17:49:21.697473Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com