CVE Database
/

CVE-2025-3722

Back to search

CVE-2025-3722

Published: Jun 26, 2025

Modified: Jun 26, 2025

PUBLISHED

Description

A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System Information Reporter, leading to creation of files anywhere on the filesystem and possibly overwriting existing files and exposing sensitive information disclosure.

VendorProductVersions

Trellix

System Information Reporter

affected
1.0.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2025-3722 - Security Vulnerability | QwikSec