{"id":"CVE-2025-36421","title":"IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.","summary":"IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-319"],"vendor":"IBM","product":"Controller","affected":["Controller >= 11.0.0 <= 11.0.1 FP7","Controller >= 11.1.0 <= 11.1.3 FP1"],"published":"2026-09-18","updated":"2026-09-19","sourceUpdated":"2026-09-19T15:16:56.660","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-36421","references":[{"url":"https://www.ibm.com/support/pages/node/7287970","label":"psirt@us.ibm.com"}],"tags":["nvd","cve.org"],"epss":0.00158,"epssPercentile":0.04175,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-19T13:45:03.739556Z"},"ingestedAt":"2026-09-18T16:45:41.377Z","slug":"CVE-2025-36421","body":"## Overview\n\nIBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":32.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}