Home

Description

A weakness has been identified in Dígitro NGC Explorer up to 3.44.15/3.48.21. This affects an unknown function. Executing a manipulation can lead to session expiration. The attack can be launched remotely. Upgrading to version 3.48.22 mitigates this issue. It is recommended to upgrade the affected component. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED Reserved 2025-05-10 | Published 2025-05-11 | Updated 2026-05-27 | Assigner VulDB




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
MEDIUM: 4.3CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
4.0AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C

Problem types

Session Expiration

Product status

3.44.0
affected

3.44.1
affected

3.44.2
affected

3.44.3
affected

3.44.4
affected

3.44.5
affected

3.44.6
affected

3.44.7
affected

3.44.8
affected

3.44.9
affected

3.44.10
affected

3.44.11
affected

3.44.12
affected

3.44.13
affected

3.44.14
affected

3.44.15
affected

3.48.0
affected

3.48.1
affected

3.48.2
affected

3.48.3
affected

3.48.4
affected

3.48.5
affected

3.48.6
affected

3.48.7
affected

3.48.8
affected

3.48.9
affected

3.48.10
affected

3.48.11
affected

3.48.12
affected

3.48.13
affected

3.48.14
affected

3.48.15
affected

3.48.16
affected

3.48.17
affected

3.48.18
affected

3.48.19
affected

3.48.20
affected

3.48.21
affected

3.48.22
unaffected

Timeline

2025-05-10:Advisory disclosed
2025-05-10:VulDB entry created
2026-05-27:VulDB entry last update

Credits

j369 (VulDB User) reporter

VulDB CNA Team coordinator

References

vuldb.com/vuln/308273 (VDB-308273 | Dígitro NGC Explorer session expiration) vdb-entry technical-description

vuldb.com/vuln/308273/cti (VDB-308273 | CTI Indicators (IOB, IOC)) signature permissions-required

vuldb.com/submit/565309 (Submit #565309 | Dígitro NGC Explorer 3.44.15 Improper session token expiration) third-party-advisory

digitro.com/recomendacao-10-2026-ctir-gov/ patch

www.gov.br/...dacoes/recomendacoes/2026/recomendacao-10-2026 related

cve.org (CVE-2025-4528)

nvd.nist.gov (CVE-2025-4528)

Download JSON