{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-15T13:07:27.929","vulnerabilities":[{"cve":{"id":"CVE-2025-3424","sourceIdentifier":"20705f08-db8b-4497-8f94-7eea62317651","published":"2025-04-07T16:15:27.703","lastModified":"2025-04-10T16:15:29.207","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"The IntelliSpace portal application utilizes .NET\nRemoting for its functionality. The vulnerability arises from the exploitation\nof port 755 through the \"Object Marshalling\" technique, which allows\nan attacker to read internal files without any authentication. This is possible\nby crafting specific .NET Remoting URLs derived from information enumerated in\nthe client-side configuration files.\n\n\n\n\n\n\n\nThis issue affects IntelliSpace Portal: 12 and prior."},{"lang":"es","value":"La aplicación de Intellispace Portal utiliza .NET Remoting para su funcionalidad. La vulnerabilidad surge de la explotación del puerto 755 mediante la técnica de \"Object Marshalling\", que permite a un atacante leer archivos internos sin autenticación. Esto es posible mediante la manipulación de URL específicas de .NET Remoting derivadas de la información enumerada en los archivos de configuración del cliente. Este problema afecta a IntelliSpace Portal: 12 y versiones anteriores."}],"metrics":{"cvssMetricV40":[{"source":"20705f08-db8b-4497-8f94-7eea62317651","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0\/AV:A\/AC:H\/AT:N\/PR:N\/UI:N\/VC:H\/VI:H\/VA:H\/SC:N\/SI:N\/SA:N\/E:X\/CR:X\/IR:X\/AR:X\/MAV:X\/MAC:X\/MAT:X\/MPR:X\/MUI:X\/MVC:X\/MVI:X\/MVA:X\/MSC:X\/MSI:X\/MSA:X\/S:P\/AU:Y\/R:U\/V:C\/RE:M\/U:Green","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"PRESENT","Automatable":"YES","Recovery":"USER","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"GREEN"}}]},"weaknesses":[{"source":"20705f08-db8b-4497-8f94-7eea62317651","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-3424","source":"20705f08-db8b-4497-8f94-7eea62317651"},{"url":"https:\/\/www.philips.com\/a-w\/security\/security-advisories.html#security_advisories","source":"20705f08-db8b-4497-8f94-7eea62317651"}]}}]}