CVE-2025-1774
Incorrect string encoding vulnerability in NASK - PIB BotSense allows injection of an additional field separator character or value in the content of some fields of the generated event. A field with additional field separator characters or values can be included in the "extraData" field.This issue affects BotSense in versions before 2.8.0.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.48%
- CWE
- CWE-142, CWE-143
- Published
- 2025-03-17
- Last modified
- 2026-03-13
Affected products
- NASK - PIB BotSense
Weakness type
Related vulnerabilities
- CVE-2026-13379 — The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to...
- CVE-2025-61962 — In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334...