CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause
arbitrary data to be written to protected locations, potentially leading to escalation of privilege, arbitrary file
corruption, exposure of application and system information or persistent denial of service when a low-privileged
attacker tampers with the installation folder.
Metrics
Affected Vendors & Products
References
History
Mon, 18 Aug 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Schneider-electric
Schneider-electric software Update Utility |
|
Vendors & Products |
Schneider-electric
Schneider-electric software Update Utility |
Mon, 18 Aug 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 18 Aug 2025 07:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary data to be written to protected locations, potentially leading to escalation of privilege, arbitrary file corruption, exposure of application and system information or persistent denial of service when a low-privileged attacker tampers with the installation folder. | |
Weaknesses | CWE-59 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: schneider
Published: 2025-08-18T07:22:05.013Z
Updated: 2025-08-18T12:22:22.123Z
Reserved: 2025-05-28T06:06:42.804Z
Link: CVE-2025-5296

Updated: 2025-08-18T12:22:19.212Z

Status : Awaiting Analysis
Published: 2025-08-18T08:15:27.820
Modified: 2025-08-18T20:16:28.750
Link: CVE-2025-5296

No data.