CVE-2025-30235 – Shearwater SecurEnvoy SecurAccess Account Brute Force

The following table lists the changes that have been made to the
CVE-2025-30235 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Mar. 19, 2025

    Action Type Old Value New Value
    Added Description Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 is intended to disable accounts that have had more than 10 failed authentication attempts, but instead allows hundreds of failed authentication attempts, because concurrent attempts are mishandled.
    Added CVSS V3.1 AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
    Added CWE CWE-362
    Added Reference https://reserge.org/probabilistically-breaking-securenvoy-totp/
    Added Reference https://securenvoy.com/wp-content/uploads/2025/03/Release-Notes-9.4.515.pdf
Share the Post:

Related Posts