A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
History

Wed, 25 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 17 Jun 2025 01:30:00 +0000

Type Values Removed Values Added
References

Tue, 17 Jun 2025 00:45:00 +0000

Type Values Removed Values Added
References

Mon, 16 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 16 Jun 2025 15:45:00 +0000


Mon, 16 Jun 2025 09:15:00 +0000

Type Values Removed Values Added
Description A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
Weaknesses CWE-367
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published: 2025-06-16T09:06:23.221Z

Updated: 2025-06-25T18:37:49.001Z

Reserved: 2025-04-09T07:11:50.443Z

Link: CVE-2025-3464

cve-icon Vulnrichment

Updated: 2025-06-16T15:03:19.071Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-16T09:15:19.233

Modified: 2025-06-17T01:15:22.120

Link: CVE-2025-3464

cve-icon Redhat

No data.