CVE-2025-34414 (CNNVD-202512-1229)
中文标题:
Entrust Instant Financial Issuance 代码问题漏洞
英文标题:
Entrust Instant Financial Issuance (IFI) Unauthenticated .NET Remoting Exposure
漏洞描述
中文描述:
Entrust Instant Financial Issuance(Entrust Cardwizard)是美国Entrust公司的一个即时金融卡发行解决方案。 Entrust Instant Financial Issuance 5.x版本、6.10.5之前版本和6.11.1之前版本存在代码问题漏洞,该漏洞源于.NET Remoting服务不安全配置,可能导致任意文件读取和远程代码执行。
英文描述:
Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the Legacy Remoting Service that is enabled by default. The service registers a TCP remoting channel with SOAP and binary formatters configured at TypeFilterLevel=Full and exposes default ObjectURI endpoints. A remote, unauthenticated attacker who can reach the remoting port can invoke the exposed remoting objects to read arbitrary files from the server and coerce outbound authentication, and may achieve arbitrary file write and remote code execution via known .NET Remoting exploitation techniques. This can lead to disclosure of sensitive installation and service-account data and compromise of the affected host.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Entrust Corporation | Instant Financial Issuance (IF) | 5.x | - | - |
cpe:2.3:a:entrust_corporation:instant_financial_issuance_(if):5.x:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
4.0 (cna)
CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-34414 |
2025-12-11 03:30:29 | 2026-01-12 02:11:32 |
| NVD | nvd_CVE-2025-34414 |
2025-12-10 04:21:19 | 2026-01-12 02:27:39 |
| CNNVD | cnnvd_CNNVD-202512-1229 |
2026-01-11 06:15:04 | 2026-01-12 02:37:55 |
版本与语言
安全公告
变更历史
查看详细变更
- references_count: 3 -> 4
查看详细变更
- vulnerability_type: 未提取 -> 代码问题
- cnnvd_id: 未提取 -> CNNVD-202512-1229
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']