An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all available settings of the IndustrialPI.
History

Wed, 02 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Jul 2025 08:15:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all available settings of the IndustrialPI.
Title Pilz: Authentication Bypass in IndustrialPI Webstatus
Weaknesses CWE-704
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published: 2025-07-01T08:10:24.679Z

Updated: 2025-07-02T13:24:37.115Z

Reserved: 2025-04-16T11:17:48.305Z

Link: CVE-2025-41648

cve-icon Vulnrichment

Updated: 2025-07-01T13:47:35.531Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-01T08:15:23.280

Modified: 2025-07-03T15:14:12.767

Link: CVE-2025-41648

cve-icon Redhat

No data.