CVE-2025-24805

2/5/2025 7:15:46 PM
یک ماه قبل
یک ماه قبل
7
Reporter :security-advisories@github.com
Modified :2/5/2025 7:15:46 PM
Problem Data :CWE-269

Description

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for materials for scopes which it should not be accepted. This issue has been addressed in version 4.3.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

Cvss Version 4.0

8.5 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction
Vulnerability Complexity High
Vulnerability Impact High

EPSS

Epss Score 0
Epss Percentile 0

Note: Consider this fact that the EPSS model relies on historical data and real-world exploit information to calculate the probability of exploitation. When a CVE is newly published, there isn't enough data available to determine its likelihood of being exploited. As a result, the EPSS score defaults to 0 until more information becomes available.