CVE-2025-0556
EUVD-2025-175312.02.2025, 16:15
In ProgressĀ® TelerikĀ® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non-sensitive information between the service agent process and app host process occurs over an unencrypted tunnel, which can be subjected to local network traffic sniffing.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| progress | telerik_report_server | 𝑥 < 11.0.25.211 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration