{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2025-3651",
        "assignerOrgId": "5d978718-751a-428d-ac8e-4f9445ebfd11",
        "state": "PUBLISHED",
        "assignerShortName": "iManage",
        "dateReserved": "2025-04-15T18:23:36.913Z",
        "datePublished": "2025-04-17T14:58:00.520Z",
        "dateUpdated": "2025-04-17T19:10:42.989Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "platforms": [
                        "MacOS"
                    ],
                    "product": "Work Desktop for Mac",
                    "vendor": "iManage",
                    "versions": [
                        {
                            "lessThan": "10.8.2.33",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        }
                    ]
                }
            ],
            "datePublic": "2025-04-17T13:00:00.000Z",
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<span style=\"background-color: rgb(255, 255, 255);\">\n\n<span style=\"background-color: rgb(255, 255, 255);\">Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions 1<span style=\"background-color: rgb(255, 255, 255);\">0.8.1.46 and earlier</span>\n\n allows attackers to execute arbitrary commands via unauthorized access to the Agent service.&nbsp;\n\n<span style=\"background-color: rgb(255, 255, 255);\">This has been remediated in Work Desktop for Mac version 10.8.2.33.</span>\n\n</span></span><p></p>"
                        }
                    ],
                    "value": "Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions 10.8.1.46 and earlier\n\n allows attackers to execute arbitrary commands via unauthorized access to the Agent service. \n\nThis has been remediated in Work Desktop for Mac version 10.8.2.33."
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-248",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-248 Command Injection"
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "attackVector": "NETWORK",
                        "baseScore": 9.3,
                        "baseSeverity": "CRITICAL",
                        "privilegesRequired": "NONE",
                        "providerUrgency": "NOT_DEFINED",
                        "subAvailabilityImpact": "NONE",
                        "subConfidentialityImpact": "HIGH",
                        "subIntegrityImpact": "HIGH",
                        "userInteraction": "PASSIVE",
                        "valueDensity": "NOT_DEFINED",
                        "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N",
                        "version": "4.0",
                        "vulnAvailabilityImpact": "NONE",
                        "vulnConfidentialityImpact": "HIGH",
                        "vulnIntegrityImpact": "HIGH",
                        "vulnerabilityResponseEffort": "NOT_DEFINED"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-346",
                            "description": "CWE-346 Origin Validation Error",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-668",
                            "description": "CWE-668 Exposure of Resource to Wrong Sphere",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "5d978718-751a-428d-ac8e-4f9445ebfd11",
                "shortName": "iManage",
                "dateUpdated": "2025-04-17T15:29:30.056Z"
            },
            "references": [
                {
                    "url": "https://docs.imanage.com/security/CVE-2025-3651.html"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "title": "Command Injection in iManage Work Desktop for Mac's Agent Service",
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-04-17T18:53:38.640700Z",
                                "id": "CVE-2025-3651",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-04-17T19:10:42.989Z"
                }
            }
        ]
    }
}