SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-62236

An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attacks.

MEDIUM 6.9EPSS 0.31%

Does this matter?

Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.

Description

The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attacks.

CVSS 4.0
6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.31% probability · 24th percentile
CISA KEV
Not listed
Weakness
CWE-204
Affected
flyfrontier/frontier airlines
Source
9119a7d8-5eab-497f-8521-727c672e3725

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.