CVE-2025-0556
Telerik Report Server vulnerability analysis and mitigation

Overview

CVE-2025-0556 affects Progress® Telerik® Report Server versions prior to 2025 Q1 (11.0.25.211). The vulnerability was discovered in February 2025 and specifically impacts installations using the older .NET Framework implementation. The issue involves cleartext transmission of non-sensitive information between the service agent process and app host process (Telerik Docs).

Technical details

The vulnerability is classified as CWE-319 (Cleartext Transmission of Sensitive Information) with a CVSS v3.1 score of 8.8 HIGH. The issue specifically pertains to the communication between the background agent service and the main application, where data is transmitted over an unencrypted tunnel. This vulnerability only affects the older .NET Framework implementation of Report Server on IIS, while the new .NET implementation is not affected (Telerik Docs).

Impact

While the CVSS score is in the high range due to the network vector, the actual impact is limited. The vulnerable communication only involves non-sensitive information related to commands between the background agent service and the main application. The traffic does not expose sensitive customer data. In default installations, where the service agent and main app are on the same system, the risk is further minimized as they do not communicate across remote networks (Telerik Docs).

Mitigation and workarounds

The recommended mitigation is to upgrade to Telerik Report Server version 2025 Q1 (11.0.25.211) or later. Users can verify their current version by logging into the Report Server web UI with administrator rights, accessing the Configuration page, and checking the version number in the About tab (Telerik Docs).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management