Nixpkgs security tracker

Login with GitHub

Suggestion detail

Dismissed
Permalink CVE-2025-15114
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • flaresolverr
    • tests.arrayUtilities.isDeclaredMap.sameScopeDeclareSingletonMap
    • tests.arrayUtilities.isDeclaredArray.sameScopeDeclareSingletonArray
    • tests.arrayUtilities.isDeclaredMap.previousScopeDeclareSingletonMapFails
    • tests.arrayUtilities.isDeclaredArray.previousScopeDeclareSingletonArrayFails
  • @LeSuisse dismissed
Ksenia Security Lares 4.0 Home Automation 1.6 PIN Exposure Vulnerability

Ksenia Security Lares 4.0 Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.

Affected products

lares
  • ==1.0.0.15
  • ==1.6
Ksenia Security Lares 4.0 Home Automation
  • ==1.0.0.15
  • ==1.6
Ignored packages (5)

pkgs.flaresolverr

Proxy server to bypass Cloudflare protection

Not present in nixpkgs