An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.
History

Wed, 23 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Apr 2025 08:00:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.
Title Forced Browsing Vulnerability in CODESYS Visualization
Weaknesses CWE-425
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published: 2025-04-23T07:54:00.430Z

Updated: 2025-04-23T16:27:02.990Z

Reserved: 2025-03-21T09:47:52.440Z

Link: CVE-2025-2595

cve-icon Vulnrichment

Updated: 2025-04-23T16:26:57.508Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-23T08:15:14.023

Modified: 2025-04-23T14:08:13.383

Link: CVE-2025-2595

cve-icon Redhat

No data.