{"api_version":"1","generated_at":"2026-07-23T11:42:49+00:00","cve":"CVE-2025-4527","urls":{"html":"https://cve.report/CVE-2025-4527","api":"https://cve.report/api/cve/CVE-2025-4527.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-4527","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-4527"},"summary":{"title":"Dígitro NGC Explorer Password Transmission client-side enforcement of server-side security","description":"A security flaw has been discovered in Dígitro NGC Explorer up to 3.44.15/3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Performing a manipulation results in client-side enforcement of server-side security. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. Upgrading to version 3.48.22 is sufficient to resolve this issue. Upgrading the affected component is recommended. The vendor was contacted early about this disclosure but did not respond in any way.","state":"PUBLISHED","assigner":"VulDB","published_at":"2025-05-11 03:15:24","updated_at":"2026-05-27 15:16:24"},"problem_types":["CWE-602","CWE-602 Client-Side Enforcement of Server-Side Security"],"metrics":[{"version":"4.0","source":"cna@vuldb.com","type":"Secondary","score":"2.9","severity":"LOW","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.9,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"DECLARED","score":"6.3","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P","data":{"baseScore":6.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P","version":"4.0"}},{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"cna@vuldb.com","type":"Secondary","score":"3.7","severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"3.7","severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C","data":{"baseScore":3.7,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C","version":"3.1"}},{"version":"3.0","source":"CNA","type":"DECLARED","score":"3.7","severity":"LOW","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C","data":{"baseScore":3.7,"baseSeverity":"LOW","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C","version":"3.0"}},{"version":"2.0","source":"cna@vuldb.com","type":"Secondary","score":"2.6","severity":"","vector":"AV:N/AC:H/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"CNA","type":"DECLARED","score":"2.6","severity":"","vector":"AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C","data":{"baseScore":2.6,"vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C","version":"2.0"}}],"references":[{"url":"https://digitro.com/recomendacao-10-2026-ctir-gov/","name":"https://digitro.com/recomendacao-10-2026-ctir-gov/","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/vuln/308272/cti","name":"https://vuldb.com/vuln/308272/cti","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/vuln/308272","name":"https://vuldb.com/vuln/308272","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.gov.br/ctir/pt-br/assuntos/alertas-e-recomendacoes/recomendacoes/2026/recomendacao-10-2026","name":"https://www.gov.br/ctir/pt-br/assuntos/alertas-e-recomendacoes/recomendacoes/2026/recomendacao-10-2026","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/submit/565308","name":"https://vuldb.com/submit/565308","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-4527","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4527","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.0","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.1","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.2","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.3","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.4","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.5","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.6","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.7","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.8","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.9","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.10","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.11","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.12","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.13","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.14","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.44.15","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.0","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.1","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.2","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.3","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.4","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.5","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.6","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.7","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.8","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.9","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.10","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.11","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.12","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.13","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.14","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.15","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.16","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.17","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.18","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.19","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.20","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"affected 3.48.21","platforms":[]},{"source":"CNA","vendor":"Dígitro","product":"NGC Explorer","version":"unaffected 3.48.22","platforms":[]}],"timeline":[{"source":"CNA","time":"2025-05-10T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"source":"CNA","time":"2025-05-10T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"source":"CNA","time":"2026-05-27T16:38:23.000Z","lang":"en","value":"VulDB entry last update"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"j369 (VulDB User)","lang":"en"},{"source":"CNA","value":"VulDB CNA Team","lang":"en"}],"nvd_cpes":[{"cve_year":"2025","cve_id":"4527","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"digitro","cpe5":"ngc_explorer","cpe6":"3.44.15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2025","cve_id":"4527","cve":"CVE-2025-4527","epss":"0.002750000","percentile":"0.510690000","score_date":"2026-06-01","updated_at":"2026-06-02 00:05:21"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-4527","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2025-05-12T14:37:44.613444Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-05-12T14:37:50.244Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:d_gitro:ngc_explorer:*:*:*:*:*:*:*:*"],"modules":["Password Transmission Handler"],"product":"NGC Explorer","vendor":"Dígitro","versions":[{"status":"affected","version":"3.44.0"},{"status":"affected","version":"3.44.1"},{"status":"affected","version":"3.44.2"},{"status":"affected","version":"3.44.3"},{"status":"affected","version":"3.44.4"},{"status":"affected","version":"3.44.5"},{"status":"affected","version":"3.44.6"},{"status":"affected","version":"3.44.7"},{"status":"affected","version":"3.44.8"},{"status":"affected","version":"3.44.9"},{"status":"affected","version":"3.44.10"},{"status":"affected","version":"3.44.11"},{"status":"affected","version":"3.44.12"},{"status":"affected","version":"3.44.13"},{"status":"affected","version":"3.44.14"},{"status":"affected","version":"3.44.15"},{"status":"affected","version":"3.48.0"},{"status":"affected","version":"3.48.1"},{"status":"affected","version":"3.48.2"},{"status":"affected","version":"3.48.3"},{"status":"affected","version":"3.48.4"},{"status":"affected","version":"3.48.5"},{"status":"affected","version":"3.48.6"},{"status":"affected","version":"3.48.7"},{"status":"affected","version":"3.48.8"},{"status":"affected","version":"3.48.9"},{"status":"affected","version":"3.48.10"},{"status":"affected","version":"3.48.11"},{"status":"affected","version":"3.48.12"},{"status":"affected","version":"3.48.13"},{"status":"affected","version":"3.48.14"},{"status":"affected","version":"3.48.15"},{"status":"affected","version":"3.48.16"},{"status":"affected","version":"3.48.17"},{"status":"affected","version":"3.48.18"},{"status":"affected","version":"3.48.19"},{"status":"affected","version":"3.48.20"},{"status":"affected","version":"3.48.21"},{"status":"unaffected","version":"3.48.22"}]}],"credits":[{"lang":"en","type":"reporter","value":"j369 (VulDB User)"},{"lang":"en","type":"coordinator","value":"VulDB CNA Team"}],"descriptions":[{"lang":"en","value":"A security flaw has been discovered in Dígitro NGC Explorer up to 3.44.15/3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Performing a manipulation results in client-side enforcement of server-side security. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. Upgrading to version 3.48.22 is sufficient to resolve this issue. Upgrading the affected component is recommended. The vendor was contacted early about this disclosure but did not respond in any way."}],"metrics":[{"cvssV4_0":{"baseScore":6.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P","version":"4.0"}},{"cvssV3_1":{"baseScore":3.7,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C","version":"3.1"}},{"cvssV3_0":{"baseScore":3.7,"baseSeverity":"LOW","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C","version":"3.0"}},{"cvssV2_0":{"baseScore":2.6,"vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C","version":"2.0"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-602","description":"Client-Side Enforcement of Server-Side Security","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-05-27T14:33:40.761Z","orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB"},"references":[{"name":"VDB-308272 | Dígitro NGC Explorer Password Transmission client-side enforcement of server-side security","tags":["vdb-entry","technical-description"],"url":"https://vuldb.com/vuln/308272"},{"name":"VDB-308272 | CTI Indicators (IOB, IOC)","tags":["signature","permissions-required"],"url":"https://vuldb.com/vuln/308272/cti"},{"name":"Submit #565308 | Dígitro NGC Explorer 3.44.15 Improper client-side encryption implementation","tags":["third-party-advisory"],"url":"https://vuldb.com/submit/565308"},{"tags":["patch"],"url":"https://digitro.com/recomendacao-10-2026-ctir-gov/"},{"tags":["related"],"url":"https://www.gov.br/ctir/pt-br/assuntos/alertas-e-recomendacoes/recomendacoes/2026/recomendacao-10-2026"}],"timeline":[{"lang":"en","time":"2025-05-10T00:00:00.000Z","value":"Advisory disclosed"},{"lang":"en","time":"2025-05-10T02:00:00.000Z","value":"VulDB entry created"},{"lang":"en","time":"2026-05-27T16:38:23.000Z","value":"VulDB entry last update"}],"title":"Dígitro NGC Explorer Password Transmission client-side enforcement of server-side security"}},"cveMetadata":{"assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","assignerShortName":"VulDB","cveId":"CVE-2025-4527","datePublished":"2025-05-11T02:00:06.268Z","dateReserved":"2025-05-10T05:29:57.658Z","dateUpdated":"2026-05-27T14:33:40.761Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-05-11 03:15:24","lastModifiedDate":"2026-05-27 15:16:24","problem_types":["CWE-602","CWE-602 Client-Side Enforcement of Server-Side Security"],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.9,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:digitro:ngc_explorer:3.44.15:*:*:*:*:*:*:*","matchCriteriaId":"E62990A8-47F0-4E03-9119-1980C3AB230E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"4527","Ordinal":"1","Title":"Dígitro NGC Explorer Password Transmission client-side enforceme","CVE":"CVE-2025-4527","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"4527","Ordinal":"1","NoteData":"A security flaw has been discovered in Dígitro NGC Explorer up to 3.44.15/3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Performing a manipulation results in client-side enforcement of server-side security. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. Upgrading to version 3.48.22 is sufficient to resolve this issue. Upgrading the affected component is recommended. The vendor was contacted early about this disclosure but did not respond in any way.","Type":"Description","Title":"Dígitro NGC Explorer Password Transmission client-side enforceme"}]}}}