CVE-2025-56577 describes a critical vulnerability in Evope Core v.1.1.3.20, where a local attacker can gain unauthorized access to sensitive information due to the use of hardcoded cryptographic keys. This vulnerability carries a high CVSS score of 8.4, indicating a significant risk with complete confidentiality, integrity, and availability impacts. While no active exploits, public exploit code, or significant community discussion have been identified, the presence of hardcoded keys presents a straightforward attack vector for a local threat actor. Organizations using Evope Core v.1.1.3.20 should prioritize patching to mitigate this severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.3.20CPE matchmatch criteria | cpe:2.3:a:evope:evope_core:1.1.3.20:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.