CVE-2025-67223 Details
Description
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls to download sensitive documents containing PII.
A vulnerability in the Aranda File Server component of Aranda Service Desk, affecting versions prior to 8.3.12, allows unauthenticated remote attackers to access daily activity logs stored in a publicly accessible directory. These logs, named with predictable formats, can be exploited to obtain direct virtual paths of uploaded files, bypassing access controls and enabling the download of sensitive documents containing personally identifiable information (PII).
Users are advised to update Aranda Service Desk to version 8.3.12 or higher. Additionally, access to the logs should be restricted by moving them outside the web root, enforcing mandatory session validation for accessing service call and incident directories, and disabling directory listing on the IIS web server.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 28, 2026CISA-ADP
Assessed Apr 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/brandonperezlara/CVE-2025-67223 | CISA-ADP | ExploitRemedy |
| https://arandasoft.com/en/productos/aranda-service-management/ | [email protected] | ProductVendor |
| https://docs.arandasoft.com/at-v8-release-notes/en/pages/release_pdf/file_server.html | [email protected] | Release NotesVendor |
| https://github.com/brandonperezlara/CVE-2025-67223 | [email protected] | ExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-377 | Insecure Temporary File | CISA-ADP |
| CWE-532 | Insertion of Sensitive Information into Log File | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Aranda Service Desk | All versions |
CPE
Remediation
| |
| Aranda File Server | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | New CVE Received | [email protected] |
Volerion