← voltar
CVE-2025-61956

Missing Authentication for Critical Function in Radiometrics VizAir

CVSS 10 CRITICALEPSS 0.7%CWE-306
Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can modify configurations without authentication, potentially manipulating active runway settings and misleading air traffic control (ATC) and pilots. Additionally, manipulated meteorological data could mislead forecasters and ATC, causing inaccurate flight planning.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Produtos afetados
Radiometrics · VizAir

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →