CVE-2025-46404 is a denial of service vulnerability affecting Entr'ouvert Lasso version 2.5.1, specifically within the lasso_provider_verify_saml_signature function. An unauthenticated attacker can trigger this vulnerability by sending a specially crafted, malformed SAML response. The vulnerability is rated as HIGH severity (CVSS 7.5), indicating it can be exploited remotely with low attack complexity, requiring no user interaction or privileges. The primary impact is a denial of service, rendering the affected system unavailable. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5.1CPE matchmatch criteria | cpe:2.3:a:entrouvert:lasso:2.5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.