go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Digiwin|EasyFlow GP - 3 Vulnerabilities

TVN ID TVN-202511008
CVE ID CVE-2025-13163, CVE-2025-13164, CVE-2025-13165
CVSS CVE-2025-13163:
4.9 (Medium) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CVE-2025-13164:
4.9 (Medium) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CVE-2025-13165:
7.5 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products EasyFlow GP version from 5.8.8.3 to 5.8.11.1.0810112:
CVE-2025-13163, CVE-2025-13164, CVE-2025-13165

EasyFlow GP version from 8.1.x to 8.1.1.2:
CVE-2025-13163, CVE-2025-13165

EasyFlow GP version from 5.7.x to 5.7.7.2:
CVE-2025-13165
Description CVE-2025-13163:
EasyFlow GP has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext database account credentials from the system frontend.

CVE-2025-13164:
EasyFlow GP has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext credentials of AD and system mail from the system frontend.

CVE-2025-13165:
EasyFlow GP has a Denial of service vulnerability, allowing unauthenticated remote attackers to send specific requests that result in denial of web service.
Solution Please update version 5.8.x to 5.8.11.1.081013 or later.
Please update version 8.1.x to 8.1.1.3 or later.
Please upgrade version 5.7.x to unaffected version or install the patch.
Credit CVE-2025-13163, CVE-2025-13164:
Tom Wang

CVE-2025-13165:
Harry Tsai(安華聯網)
Public Date 2025-11-17
Top