← back
CVE-2025-12508highCWE-319

Unencrypted communication to Active Directory services

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.4epss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to the interception of authentication data and compromise confidentiality.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Affected products
Bizerba · BRAIN2