CVE-2025-3716: User enumeration in ESET Protect (on-prem)
Published Mar 30, 2026
·Updated
User enumeration in ESET Protect (on-prem) via Response Timing.
Affected Software
1 affected component
ESET ESET Protect (on-prem)
Event History
Mar 30, 2026
CVE Published
via MITRE·07:30 AM
Data Sourced
via MITRE·07:30 AM
DescriptionWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-3716?
CVE-2025-3716 has a moderate severity rating due to its potential for user enumeration.
2
How do I fix CVE-2025-3716?
Fixing CVE-2025-3716 involves updating ESET Protect to the latest version where the vulnerability has been patched.
3
What is user enumeration in CVE-2025-3716?
User enumeration in CVE-2025-3716 refers to the ability to differentiate valid usernames from invalid ones through response timing.
4
Which versions of ESET Protect are affected by CVE-2025-3716?
CVE-2025-3716 affects all versions of ESET Protect (on-prem) prior to the security update.
5
How can CVE-2025-3716 impact my security?
CVE-2025-3716 can impact security by allowing attackers to gather valid usernames, potentially leading to further attacks.