CVE-2025-61792
BaseFortify
Publication date: 2025-09-30
Last updated on: 2025-10-02
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-362 | The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves a race condition in Quadient DS-700 iQ devices that can occur when quickly clicking a sequence of buttons (Question Mark, Help, About, Help). This race condition might cause the device to exit kiosk mode and grant local administrative access. However, the behavior was observed sporadically and may not be reliably reproducible. It is also unclear if the issue is due to software or hardware faults, and the risk is generally limited to insider threats in specific environments.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow an attacker to gain local administrative access to the device by exiting kiosk mode unexpectedly. This could lead to unauthorized control over the device, potentially compromising its security and functionality. However, the vulnerability appears to be sporadic and may not be easily reproducible, limiting the practical impact.