Description
A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder.
Published: 2025-06-26
Score: 0 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-27857 A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder.
History

Wed, 11 Feb 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Trellix
Trellix system Information Reporter
CPEs cpe:2.3:a:trellix:system_information_reporter:*:*:*:*:*:*:*:*
Vendors & Products Trellix
Trellix system Information Reporter
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Thu, 26 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Jun 2025 11:30:00 +0000

Type Values Removed Values Added
Description A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder.
Weaknesses CWE-530
References
Metrics cvssV4_0

{'score': 0, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Trellix System Information Reporter
cve-icon MITRE

Status: PUBLISHED

Assigner: trellix

Published:

Updated: 2025-06-26T12:58:54.131Z

Reserved: 2025-04-17T16:11:49.823Z

Link: CVE-2025-3773

cve-icon Vulnrichment

Updated: 2025-06-26T12:58:51.485Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-26T12:15:21.713

Modified: 2026-02-11T21:39:41.160

Link: CVE-2025-3773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses