# CVE-2025-3773

## Summary

- **CVE ID:** CVE-2025-3773
- **Severity:** UNKNOWN
- **CVSS Score:** 0 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-530
- **Published:** Jun 26, 2025
- **Last Modified:** Mar 12, 2026

## Description

A sensitive  information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder.

## Affected Products

- Trellix — System Information Reporter (1.0.3)

## References

- [CNA](https://thrive.trellix.com/s/article/000014635)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.12%
- **EPSS Percentile:** 2.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._