CVE 7.5 HIGH

Senstar Symphony FetchStoredLicense Information Disclosure Vulnerability_CVE-2025-12491

7.5 / 10
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Senstar Symphony FetchStoredLicense Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Senstar Symphony. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the implementation of FetchStoredLicense method. The issue results from the exposure of sensitive information. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-26908.

Basic Information

ID CVE-2025-12491
Source zdi
Published Dec 23, 2025 at 21:43

Affected Product

Vendor Senstar
Product Symphony
Version 8.9.4.0
Affected Versions Senstar Symphony 8.9.4.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.