CVE-2025-0556

In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non-sensitive information between the service agent process and app host process occurs over an unencrypted tunnel, which can be subjected to local network traffic sniffing.
Configurations

Configuration 1 (hide)

cpe:2.3:a:progress:telerik_report_server:*:*:*:*:*:*:*:*

History

20 Feb 2025, 20:41

Type Values Removed Values Added
Summary
  • (es) En Progress® Telerik® Report Server, versiones anteriores a 2025 Q1 (11.0.25.211) cuando se utiliza la implementación .NET framework más antigua, la comunicación de información no confidencial entre el proceso del agente de servicio y el proceso del host de la aplicación se produce a través de un túnel no cifrado, que puede estar sujeto al rastreo del tráfico de la red local.
First Time Progress
Progress telerik Report Server
CPE cpe:2.3:a:progress:telerik_report_server:*:*:*:*:*:*:*:*
References () https://docs.telerik.com/report-server/knowledge-base/kb-security-cleartext-transmission-cve-2025-0556 - () https://docs.telerik.com/report-server/knowledge-base/kb-security-cleartext-transmission-cve-2025-0556 - Vendor Advisory

12 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-12 16:15

Updated : 2025-02-20 20:41


NVD link : CVE-2025-0556

Mitre link : CVE-2025-0556

CVE.ORG link : CVE-2025-0556


JSON object : View

Products Affected

progress

  • telerik_report_server
CWE
CWE-319

Cleartext Transmission of Sensitive Information