CVE-2019-25599 is a medium-severity denial of service vulnerability affecting Backup Key Recovery 2.2.4, allowing a local attacker to crash the application. This vulnerability, with a CVSS score of 6.2, is triggered by supplying an excessively long string (300+ characters) in the Name field during registration, leading to application unavailability. The attack requires local access and no user interaction. There is currently no evidence of active exploitation, no public exploit code available in common databases like Metasploit or ExploitDB, and no community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Nsauditor | Backup Key Recovery | 2.2.4CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.