# CVE-2025-1774

## Summary

- **CVE ID:** CVE-2025-1774
- **Severity:** MEDIUM
- **CVSS Score:** 6.3 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-142, CWE-143
- **Published:** Mar 17, 2025
- **Last Modified:** Mar 13, 2026

## Description

Incorrect string encoding vulnerability in NASK - PIB BotSense allows injection of an additional field separator character or value in the content of some fields of the generated event. A field with additional field separator characters or values can be included in the "extraData" field.This issue affects BotSense in versions before 2.8.0.

## Affected Products

- NASK - PIB — BotSense (0)

## References

- [CNA](https://cert.pl/en/posts/2025/03/CVE-2025-1774/)
- [CNA](https://cert.pl/posts/2025/03/CVE-2025-1774/)
- [CNA](https://nask.pl/instytut/dla-biznesu/botsense/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.48%
- **EPSS Percentile:** 39.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._