Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-32899

Опубликовано: 05 дек. 2025
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically, it is an invalid discovery packet sent over broadcast UDP.

A flaw was found in KDE Connect. This vulnerability allows two paired devices to unpair via an invalid discovery packet sent over broadcast User Datagram Protocol (UDP).

Отчет

This vulnerability is rated Moderate for Red Hat as it allows an unauthenticated attacker on the same local network segment to unpair KDE Connect devices. This flaw primarily impacts the availability of the KDE Connect service by disrupting established device pairings.

Меры по смягчению последствий

To mitigate this issue, restrict network access to systems running KDE Connect. Configure firewall rules to limit UDP traffic on the KDE Connect discovery port (default 1716) to only allow communication from trusted hosts or subnets. This may impact the ability of KDE Connect to discover and pair with new devices if not configured correctly.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1250
https://bugzilla.redhat.com/show_bug.cgi?id=2419077kde-connect: KDE Connect: Unpairing of devices via invalid broadcast UDP packet

EPSS

Процентиль: 7%
0.00175
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
9 месяцев назад

In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically, it is an invalid discovery packet sent over broadcast UDP.

CVSS3: 4.3
nvd
9 месяцев назад

In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically, it is an invalid discovery packet sent over broadcast UDP.

CVSS3: 4.3
github
9 месяцев назад

In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically, it is an invalid discovery packet sent over broadcast UDP.

EPSS

Процентиль: 7%
0.00175
Низкий

4.3 Medium

CVSS3