CVE Explorer
CVE-2025-63579
Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive information can be obtained. This affects Kyocera Command Center RX TASKalfa 2552ci, TASKalfa 3252ci, TASKalfa 2553ci, TASKalfa 3253ci, TASKalfa 3554ci, TASKalfa 4052ci, TASKalfa 5052ci, TASKalfa 6052ci, TASKalfa 7052ci, TASKal
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 5 assertions
{"cweId":"CWE-200","description":"CWE-200 Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f063fa34f5ab62354b3a368012fb458cb0c968b7dffee5b1dd81fa7126a9ea1a · sha256:e4bff4b13247fe08… · /containers/adp/0/problemTypes/0/descriptions/0
{"cweId":"CWE-326","description":"CWE-326 Inadequate Encryption Strength","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f063fa34f5ab62354b3a368012fb458cb0c968b7dffee5b1dd81fa7126a9ea1a · sha256:e4bff4b13247fe08… · /containers/adp/0/problemTypes/3/descriptions/0
{"cweId":"CWE-311","description":"CWE-311 Missing Encryption of Sensitive Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f063fa34f5ab62354b3a368012fb458cb0c968b7dffee5b1dd81fa7126a9ea1a · sha256:e4bff4b13247fe08… · /containers/adp/0/problemTypes/1/descriptions/0
{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f063fa34f5ab62354b3a368012fb458cb0c968b7dffee5b1dd81fa7126a9ea1a · sha256:e4bff4b13247fe08… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f063fa34f5ab62354b3a368012fb458cb0c968b7dffee5b1dd81fa7126a9ea1a · sha256:e4bff4b13247fe08… · /containers/adp/0/problemTypes/2/descriptions/0
Affected products and versions
1 source assertion{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f063fa34f5ab62354b3a368012fb458cb0c968b7dffee5b1dd81fa7126a9ea1a · sha256:e4bff4b13247fe08… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f063fa34f5ab62354b3a368012fb458cb0c968b7dffee5b1dd81fa7126a9ea1a · sha256:e4bff4b13247fe08… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
5 source assertions{"cweId":"CWE-200","description":"CWE-200 Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f063fa34f5ab62354b3a368012fb458cb0c968b7dffee5b1dd81fa7126a9ea1a · sha256:e4bff4b13247fe08… · /containers/adp/0/problemTypes/0/descriptions/0
{"cweId":"CWE-326","description":"CWE-326 Inadequate Encryption Strength","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f063fa34f5ab62354b3a368012fb458cb0c968b7dffee5b1dd81fa7126a9ea1a · sha256:e4bff4b13247fe08… · /containers/adp/0/problemTypes/3/descriptions/0
{"cweId":"CWE-311","description":"CWE-311 Missing Encryption of Sensitive Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f063fa34f5ab62354b3a368012fb458cb0c968b7dffee5b1dd81fa7126a9ea1a · sha256:e4bff4b13247fe08… · /containers/adp/0/problemTypes/1/descriptions/0
{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f063fa34f5ab62354b3a368012fb458cb0c968b7dffee5b1dd81fa7126a9ea1a · sha256:e4bff4b13247fe08… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f063fa34f5ab62354b3a368012fb458cb0c968b7dffee5b1dd81fa7126a9ea1a · sha256:e4bff4b13247fe08… · /containers/adp/0/problemTypes/2/descriptions/0
Source references
2 source assertions{"url":"https://github.com/barisbaydur/CVE-2025-63579"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f063fa34f5ab62354b3a368012fb458cb0c968b7dffee5b1dd81fa7126a9ea1a · sha256:e4bff4b13247fe08… · /containers/cna/references/0
{"url":"https://global.kyocera.com/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f063fa34f5ab62354b3a368012fb458cb0c968b7dffee5b1dd81fa7126a9ea1a · sha256:e4bff4b13247fe08… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.