This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker could exploit this vulnerability by accessing certain unauthorized API endpoints leading to detailed error messages as response leading to disclosure of system related information.
History

Wed, 23 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Apr 2025 11:00:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker could exploit this vulnerability by accessing certain unauthorized API endpoints leading to detailed error messages as response leading to disclosure of system related information.
Title Detailed Error Response Vulnerability in Meon KYC solutions
Weaknesses CWE-1295
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2025-04-23T10:43:56.953Z

Updated: 2025-04-23T14:44:52.451Z

Reserved: 2025-04-16T12:00:23.726Z

Link: CVE-2025-42604

cve-icon Vulnrichment

Updated: 2025-04-23T14:44:42.517Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-23T11:15:47.190

Modified: 2025-04-23T14:08:13.383

Link: CVE-2025-42604

cve-icon Redhat

No data.