MEDIUM
Comodo Dragon IP DNS Leakage Detector cleartext transmission
Published Jul 26, 2025
6.3
MEDIUMCVSS 4.0
EPSS 0.45%
Description
A vulnerability, which was classified as problematic, has been found in Comodo Dragon up to 134.0.6998.179. Affected by this issue is some unknown functionality of the component IP DNS Leakage Detector. The manipulation leads to cleartext transmission of sensitive information. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 134.0.6998.179StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-22801 Advisory
- https://news.fmisec.com/comodo-dragon-vulnerability exploitThird Party Advisory
- https://vuldb.com/?ctiid.317774 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.317774 vdb-entryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-22801 | Advisory | |
| https://news.fmisec.com/comodo-dragon-vulnerability | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.317774 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.317774 | vdb-entryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jul 26, 2025
Updated Jul 28, 2025
Reserved Jul 25, 2025
Link CVE-2025-8205
CISA Vulnrichment
Updated Jul 28, 2025
ENISA EUVD
EUVD-2025-22801 Assigner VulDB
Published Jul 26, 2025
Updated Jul 28, 2025
Exploited since n/a
Link EUVD-2025-22801