CVE-2025-47872
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
08/08/2025
Last modified:
08/08/2025
Description
The public-facing product registration endpoint server responds <br />
differently depending on whether the S/N is valid and unregistered, <br />
valid but already registered, or does not exist in the database. <br />
Combined with the fact that serial numbers are sequentially assigned, <br />
this allows an attacker to gain information on the product registration <br />
status of different S/Ns.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
5.80
Severity 3.x
MEDIUM



