CVE-2025-32803 describes a vulnerability in Kea versions 2.4.0-2.4.1, 2.6.0-2.6.2, and 2.7.0-2.7.8, where log or lease files may be world-readable, potentially exposing sensitive information. Rated Medium with a CVSS score of 4.0, this local vulnerability requires no user interaction and could lead to information disclosure (C:L). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.0, <= 2.4.1CPE match | cpe:2.3:a:isc:kea:*:*:*:*:*:*:*:* | ||
>= 2.6.0, <= 2.6.2CPE match | cpe:2.3:a:isc:kea:*:*:*:*:*:*:*:* | ||
>= 2.7.0, <= 2.7.8CPE match | cpe:2.3:a:isc:kea:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.