Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated remote access to an active FTP account containing sensitive internal data and import structures. In environments where this FTP server is part of automated business processes (e.g. EDI or data integration), this could lead to data manipulation, extraction, or abuse.  Debug ports 1602, 1603 and 1636 also expose service architecture information and system activity logs
History

Mon, 25 Aug 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Minova
Minova tta
Vendors & Products Minova
Minova tta

Mon, 25 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 25 Aug 2025 09:00:00 +0000

Type Values Removed Values Added
Description Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated remote access to an active FTP account containing sensitive internal data and import structures. In environments where this FTP server is part of automated business processes (e.g. EDI or data integration), this could lead to data manipulation, extraction, or abuse.  Debug ports 1602, 1603 and 1636 also expose service architecture information and system activity logs
Title MINOVA TTA Information Disclosure and Credential Exposure
Weaknesses CWE-200
CWE-312
CWE-532
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published: 2025-08-25T08:52:47.797Z

Updated: 2025-08-25T13:47:36.182Z

Reserved: 2025-07-10T09:22:44.017Z

Link: CVE-2025-7426

cve-icon Vulnrichment

Updated: 2025-08-25T13:47:13.690Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-25T09:15:29.110

Modified: 2025-08-25T20:24:45.327

Link: CVE-2025-7426

cve-icon Redhat

No data.