Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-1882


A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality of the component Device Setting Handler. The manipulation leads to improper access control for register interface. The attack needs to be done within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.


Published

2025-03-03T21:15:18.267

Last Modified

2025-03-05T15:18:54.127

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.0 (MEDIUM)

CVSSv2 Vector

AV:A/AC:H/Au:N/C:P/I:P/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.2

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-284
    CWE-1262
  • Type: Secondary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System i-drive i11_firmware ≤ 20250227 Yes
Hardware i-drive i11 * No
Operating System i-drive i12_firmware ≤ 20250227 Yes
Hardware i-drive i12 * No

References