{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-15610", "assignerOrgId": "f81092c5-7f14-476d-80dc-24857f90be84", "state": "PUBLISHED", "assignerShortName": "OpenText", "dateReserved": "2026-03-16T14:20:32.991Z", "datePublished": "2026-04-15T16:31:53.959Z", "dateUpdated": "2026-04-29T22:07:10.628Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "f81092c5-7f14-476d-80dc-24857f90be84", "shortName": "OpenText", "dateUpdated": "2026-04-29T22:07:10.628Z" }, "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-502", "description": "CWE-502 Deserialization of untrusted data", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-586", "descriptions": [ { "lang": "en", "value": "CAPEC-586 Object Injection" } ] } ], "affected": [ { "vendor": "OpenText, Inc", "product": "RightFax", "platforms": [ "Windows", "64 bit", "32 bit" ], "versions": [ { "status": "affected", "version": "16.6", "lessThanOrEqual": "16.6 Update7136", "versionType": "custom" }, { "status": "affected", "version": "20.2", "lessThanOrEqual": "20.2 Update5705", "versionType": "custom" }, { "status": "affected", "version": "21.2", "lessThanOrEqual": "21.2.1.2707", "versionType": "custom" }, { "status": "affected", "version": "22.2", "lessThanOrEqual": "22.2.0.1644", "versionType": "custom" }, { "status": "affected", "version": "23.4", "lessThanOrEqual": "26.4.0.1644", "versionType": "custom" }, { "status": "affected", "version": "24.4", "lessThanOrEqual": "24.4.0.1644", "versionType": "custom" }, { "status": "affected", "version": "25.4", "lessThanOrEqual": "25.4.0.1644", "versionType": "custom" } ], "defaultStatus": "unknown" } ], "descriptions": [ { "lang": "en", "value": "The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed in environments where the remoting ports are accessible.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed in environments where the remoting ports are accessible." } ] } ], "references": [ { "url": "https://support.opentext.com/csm?id=ot_kb_unauthenticated&sysparm_article=KB0861863" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "NONE", "userInteraction": "NONE", "vulnConfidentialityImpact": "HIGH", "subConfidentialityImpact": "NONE", "vulnIntegrityImpact": "HIGH", "subIntegrityImpact": "NONE", "vulnAvailabilityImpact": "HIGH", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "CRITICAL", "baseScore": 9.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } } ], "credits": [ { "lang": "en", "value": "Harrison Neal", "type": "finder" } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 1.0.1" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-04-15T17:32:21.163911Z", "id": "CVE-2025-15610", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-04-15T17:32:31.254Z" } } ] } }