Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-1880


A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as problematic. Affected is an unknown function of the component Device Pairing. The manipulation leads to authentication bypass by primary weakness. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitability is told to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.


Published

2025-03-03T20:15:45.717

Last Modified

2025-03-05T14:51:33.507

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 2.0 (LOW)

CVSSv2 Vector

AV:L/AC:H/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

1.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-287
    CWE-305

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System i-drive i11_firmware ≤ 20250227 Yes
Hardware i-drive i11 * No
Operating System i-drive i12_firmware ≤ 20250227 Yes
Hardware i-drive i12 * No

References