Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.
History

Mon, 11 Aug 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 11 Aug 2025 09:15:00 +0000

Type Values Removed Values Added
Description Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.
Title 2100 Technology|Official Document Management System - Authentication Bypass
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2025-08-11T09:04:20.323Z

Updated: 2025-08-11T12:50:27.146Z

Reserved: 2025-08-11T02:24:36.145Z

Link: CVE-2025-8853

cve-icon Vulnrichment

Updated: 2025-08-11T12:50:24.075Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-11T09:15:30.467

Modified: 2025-08-11T18:32:48.867

Link: CVE-2025-8853

cve-icon Redhat

No data.