CVE-2025-30236: High severity Shearwater SecurEnvoy SecurAccess vulnerability
Published Mar 19, 2025
·Updated
Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authentication through only a six-digit TOTP code (skipping a password check) if an HTTP POST request contains a SESSION parameter.
Affected Software
1 affected component
Shearwater SecurEnvoy SecurAccess<9.4.515
Event History
Mar 19, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Mar 15, 57195
Event
via FIRST·08:48 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-30236?
CVE-2025-30236 is classified as a high severity vulnerability due to its potential for bypassing authentication mechanisms.
2
How do I fix CVE-2025-30236?
To mitigate CVE-2025-30236, upgrade Shearwater SecurEnvoy SecurAccess to version 9.4.515 or later.
3
What types of attacks does CVE-2025-30236 allow?
CVE-2025-30236 allows attackers to authenticate without a password using only a six-digit TOTP code.
4
Which version of Shearwater SecurEnvoy is affected by CVE-2025-30236?
CVE-2025-30236 affects Shearwater SecurEnvoy SecurAccess versions prior to 9.4.515.
5
How does the vulnerability in CVE-2025-30236 occur?
The vulnerability in CVE-2025-30236 occurs when an HTTP POST request contains a SESSION parameter, allowing authentication bypass.