CVE-2025-58385
7.1DOXENSE · WATCHDOC
DOXENSE WATCHDOC versions prior to 6.1.0.5094 contain a vulnerability where private user PUK codes for Active Directory registered users can be disclosed due to hard-coded and predictable data.
Executive summary
A vulnerability in DOXENSE WATCHDOC allows for the unauthorized disclosure of sensitive user PUK codes, posing a significant risk to organizational authentication security.
Vulnerability
The software utilizes hard-coded and predictable data to generate private user PUK codes, which can be disclosed to unauthorized parties. This flaw does not require authentication to exploit, as indicated by the CVSS vector.
Business impact
The exposure of PUK codes for Active Directory users represents a critical failure in identity management, potentially allowing attackers to bypass secondary authentication or gain unauthorized access to protected resources. Given the CVSS score of 7.1, this vulnerability is considered high risk because it compromises the integrity of user credentials. Failure to remediate could lead to widespread account takeovers and internal privilege escalation within the affected environment.
Remediation
Immediate Action: Organizations must update the WATCHDOC software to version 6.1.0.5094 or later as specified in the official vendor advisory.
Proactive Monitoring: Security teams should review application and authentication logs for anomalous access patterns or unauthorized attempts to retrieve user credential information.
Compensating Controls: Ensure that the WATCHDOC management interface is restricted to authorized internal networks and is not accessible from the public internet to reduce the potential attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The reliance on predictable data for sensitive security tokens like PUK codes is a severe flaw that necessitates immediate remediation. Administrators should prioritize upgrading to the patched version identified by DOXENSE to prevent the potential disclosure of user credentials. Until the update is applied, ensure that access to the affected system is strictly limited to trusted personnel and monitored for suspicious activity.