CVE-2025-47872

The public-facing product registration endpoint server responds 
differently depending on whether the S/N is valid and unregistered, 
valid but already registered, or does not exist in the database. 
Combined with the fact that serial numbers are sequentially assigned, 
this allows an attacker to gain information on the product registration 
status of different S/Ns.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
icscertCNA
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
CISA-ADPADP
---
---