Authentication Bypass in Sechard Information Technologies' SecHard
Summary
| CVE | CVE-2025-2311 |
|---|---|
| State | PUBLISHED |
| Assigner | TR-CERT |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-03-20 12:15:14 UTC |
| Updated | 2026-06-06 08:16:51 UTC |
| Description | Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring. This issue affects SecHard: before 3.3.0.20220411. |
Risk And Classification
Primary CVSS: v3.1 9 CRITICAL from [email protected]
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Problem Types: CWE-319 | CWE-522 | CWE-648 | CWE-648 CWE-648 Incorrect Use of Privileged APIs | CWE-319 CWE-319 Cleartext Transmission of Sensitive Information | CWE-522 CWE-522 Insufficiently Protected Credentials
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9 | CRITICAL | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9 | CRITICAL | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Sechard Information Technologies | SecHard | affected 3.3.0.20220411 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.usom.gov.tr/bildirim/tr-25-0074 | [email protected] | www.usom.gov.tr | |
| siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0074 | [email protected] | siberguvenlik.gov.tr | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Berat Ugur DEMIRKAN (en)
CNA: BG-TEK Cyber Security (en)
There are currently no legacy QID mappings associated with this CVE.