CVE-2025-2185 Details
Description
ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which could permit an attacker to transmit passwords over unencrypted connections, resulting in the product becoming vulnerable to interception.
A vulnerability exists in ALBEDO Telecom Net.Time - PTP/NTP clock, specifically in software release 1.4.4 (Serial No. NBC0081P). The issue arises from insufficient session expiration, which could allow an attacker to send passwords over unencrypted connections, making the product susceptible to interception.
Users are advised to update the Net.Time - PTP/NTP clock to version 1.6.1. For more information, contact ALBEDO Telecom.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 25, 2025CISA-ADP
Assessed Apr 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.albedotelecom.com/contactus.php | [email protected] | Vendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-02 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ALBEDO Telecom Net.Time | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 25, 2025 | New CVE Received | [email protected] |
Volerion