CVE-2025-3424

Severity CVSS v4.0:
HIGH
Type:
CWE-22 Path Traversal
Publication date:
07/04/2025
Last modified:
10/04/2025

Description

The IntelliSpace portal application utilizes .NET<br /> Remoting for its functionality. The vulnerability arises from the exploitation<br /> of port 755 through the "Object Marshalling" technique, which allows<br /> an attacker to read internal files without any authentication. This is possible<br /> by crafting specific .NET Remoting URLs derived from information enumerated in<br /> the client-side configuration files.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> This issue affects IntelliSpace Portal: 12 and prior.