CVE-2025-65320
BaseFortify
Publication date: 2025-12-03
Last updated on: 2025-12-18
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| abacre | restaurant_point_of_sale | to 15.0.0.1656 (exc) |
| abacre | restaurant_point_of_sale | 15.0.0.1656 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-312 | The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves Abacre Restaurant Point of Sale (POS) software versions up to 15.0.0.1656, where valid device-bound license keys are left in cleartext in the process memory during an activation attempt. This means sensitive license information is stored in memory without encryption, potentially exposing it to unauthorized access.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access to sensitive license keys stored in memory, which could be exploited by attackers to bypass licensing restrictions or compromise the software's integrity. This may result in software misuse or unauthorized use of licensed features.