CVE Vulnerabilities

CVE-2025-3895

Small Space of Random Values

Published: May 23, 2025 | Modified: May 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with a queryable value. It allows an unauthenticated attacker who know user login names to brute force these tokens and change account passwords (including these belonging to administrators).  Version 5.20 of MegaBIP fixes this issue.

Weakness

The number of possible random values is smaller than needed by the product, making it more susceptible to brute force attacks.

Potential Mitigations

References