CVE-2025-50572

high

Description

An issue was discovered in Archer Technology RSA Archer 6.11.00204.10014 allowing attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be executed after the user opened the file with compatible applications.

References

https://github.com/shorooq-hummdi/Archer-csv-injection-command-exec/blob/main/README.md

http://rsa.com

http://archer.com

Details

Source: Mitre, NVD

Published: 2025-07-31

Updated: 2025-08-04

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00045