| TVN ID | TVN-202511008 |
|---|---|
| CVE ID | CVE-2025-13163, CVE-2025-13164, CVE-2025-13165 |
| CVSS | CVE-2025-13163: 4.9 (Medium) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVE-2025-13164: 4.9 (Medium) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVE-2025-13165: 7.5 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| Affected Products | EasyFlow GP version from 5.8.8.3 to 5.8.11.1.0810112: CVE-2025-13163, CVE-2025-13164, CVE-2025-13165 EasyFlow GP version from 8.1.x to 8.1.1.2: CVE-2025-13163, CVE-2025-13165 EasyFlow GP version from 5.7.x to 5.7.7.2: CVE-2025-13165 |
| Description | CVE-2025-13163: EasyFlow GP has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext database account credentials from the system frontend. CVE-2025-13164: EasyFlow GP has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext credentials of AD and system mail from the system frontend. CVE-2025-13165: EasyFlow GP has a Denial of service vulnerability, allowing unauthenticated remote attackers to send specific requests that result in denial of web service. |
| Solution | Please update version 5.8.x to 5.8.11.1.081013 or later. Please update version 8.1.x to 8.1.1.3 or later. Please upgrade version 5.7.x to unaffected version or install the patch. |
| Credit | CVE-2025-13163, CVE-2025-13164: Tom Wang CVE-2025-13165: Harry Tsai(安華聯網) |
| Public Date | 2025-11-17 |
