CVE Details
Basic Information
| Title | CVE-2025-3895 |
|---|---|
| Type | cve |
| Published | 2025-05-23T11:15:32 |
| Last Seen | 2025-05-23T12:27:18 |
CVSS Information
| Base Score | 0.0 () |
|---|---|
| Attack Vector | |
| Attack Complexity | |
| Privileges Required | |
| User Interaction | |
| Scope | |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | The vulnerability in MegaBIP software allows an unauthenticated attacker to exploit the small space of random values used in password reset tokens, potentially compromising user accounts. This issue is exacerbated by the use of queryable values, making it easier for attackers to guess or brute-force the tokens. The impact is significant as it affects the security of user accounts and could lead to unauthorized access. |
|---|---|
| AI Severity | Critical |
| Vendor | MegaBIP |
| Product | MegaBIP |
| Affected Version |
Additional Information
| CVE List | CVE-2025-3895 |
|---|---|
| CWE List | CWE-334 |
| Bulletin Family | cve |
Description
Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with a queryable value. It allows an unauthenticated attacker who know user login names to…
CVSS Score Summary
Base Score: %!f(string=#) ()