HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36 with Servicepack 8 (week 36/2025), which allows an attacker to read arbitrary files from the Windows operating system. The "Filename" parameter of the public $SCHEMAS$ ressource is vulnerable and can be exploited easily.

Project Subscriptions

Vendors Products
Microsoft Subscribe
Windows Subscribe
Mpdv Mikrolab Subscribe
Advisories

No advisories yet.

Fixes

Solution

The vulnerability is fixed in the following version: * Maintenance Pack of week 36/2025 for MIP2 / FEDRA2 / HYDRA X with Servicepack 8 Customers can download the patch from the vendor's support portal.


Workaround

No workaround given by the vendor.

History

Mon, 03 Nov 2025 18:30:00 +0000

Type Values Removed Values Added
References

Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Mpdv Mikrolab
Mpdv Mikrolab fedra 2
Mpdv Mikrolab hydra X
Mpdv Mikrolab mip 2
Vendors & Products Microsoft
Microsoft windows
Mpdv Mikrolab
Mpdv Mikrolab fedra 2
Mpdv Mikrolab hydra X
Mpdv Mikrolab mip 2

Mon, 27 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 07:00:00 +0000

Type Values Removed Values Added
Description HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36 with Servicepack 8 (week 36/2025), which allows an attacker to read arbitrary files from the Windows operating system. The "Filename" parameter of the public $SCHEMAS$ ressource is vulnerable and can be exploited easily.
Title Unauthenticated Local File Disclosure in MPDV Mikrolab MIP 2 / FEDRA 2 / HYDRA X Manufacturing Execution System
Weaknesses CWE-22
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published:

Updated: 2025-11-03T17:32:04.323Z

Reserved: 2025-10-22T06:45:51.500Z

Link: CVE-2025-12055

cve-icon Vulnrichment

Updated: 2025-11-03T17:32:04.323Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-27T07:15:37.727

Modified: 2025-11-03T18:15:48.737

Link: CVE-2025-12055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-27T22:04:02Z

Weaknesses