CVE-2025-5087
BaseFortify
Publication date: 2025-06-24
Last updated on: 2025-06-26
Assigner: ICS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-319 | The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves Kaleris NAVIS N4 ULC (Ultra Light Client) communicating insecurely by using zlib-compressed data over HTTP. Because the communication is not properly secured, an attacker who can observe the network traffic between the Ultra Light Clients and N4 servers can extract sensitive information, including plaintext credentials.
How can this vulnerability impact me? :
The vulnerability can lead to exposure of sensitive information such as plaintext credentials if an attacker is able to intercept the network traffic. This could result in unauthorized access to systems or data, potentially compromising security and privacy.