CVE-2025-53703
BaseFortify
Publication date: 2025-07-22
Last updated on: 2025-07-25
Assigner: ICS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| duracomm | spm-500 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-319 | The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the DuraComm SPM-500 DP-10iN-100-MU device transmitting sensitive data without encryption over a communication channel. Because the data is sent unencrypted, attackers could potentially intercept and access this sensitive information.
How can this vulnerability impact me? :
The impact of this vulnerability is that sensitive data transmitted by the device can be intercepted by attackers, leading to potential data breaches or unauthorized access to confidential information. This could compromise the security and privacy of the data being transmitted.