PT-2025-49141 · Unknown · Solstice Pod Api
CVE-2025-66573
·
Publicado
2025-12-04
·
Atualizado
2025-12-05
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Solstice Pod API versions 5.5 through 6.2
Description
The Solstice Pod API has an unauthenticated API endpoint. Specifically, the
/api/config endpoint allows unauthorized access to sensitive information without requiring authentication. This exposed data includes the session key, server version, product details, and display name. Accessing this endpoint allows extraction of live session information.Recommendations
Apply authentication to the
/api/config API endpoint for versions 5.5 through 6.2.Exploit
Correção
Cleartext Transmission of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Solstice Pod Api