CVE-2025-62643
BaseFortify
Publication date: 2025-10-17
Last updated on: 2025-10-31
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| rbi | restaurant_brands_international_assistant | to 2025-09-06 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-319 | The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the Restaurant Brands International (RBI) assistant platform transmitting user account passwords in cleartext within email messages. This means that passwords are sent without encryption, making them potentially accessible to unauthorized parties who intercept the emails.
How can this vulnerability impact me? :
Because passwords are transmitted in cleartext emails, attackers who intercept these emails could obtain user passwords, leading to unauthorized access to user accounts. This compromises account security and could result in data breaches or unauthorized actions within the affected platform.