CVE Vulnerabilities

CVE-2025-34183

Insertion of Sensitive Information into Log File

Published: Sep 16, 2025 | Modified: Sep 25, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential reuse.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Eve_x1_server_firmware Ilevia * 4.7.18.0 (including)

Potential Mitigations

References