Description

A Cleartext Transmission of Sensitive Information vulnerability (CWE-319) in Dolusoft Omaspot allows interception and privilege escalation. Affects versions before 12.09.2025. CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.

CVSS Vector

Primary assessmentCNA · 9.6 CriticalCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: AdjacentAC: LowPR: NoneUI: NoneS: ChangedC: HighI: HighA: High

References

Record Verification

CreditThe official CVE record credits Sevban Donmez as finder
PublishedThe CVE record was published on 2025-09-16
CheckedMetadata last checked against the CVE Services record on 2026-08-23