The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executable for the BCS service, malicious programs can be executed.
Advisories

No advisories yet.

Fixes

Solution

Update to version ≥ 5.02


Workaround

Enclose the service path in the registry in quotes: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BCS\ImagePath

History

Fri, 31 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 16:00:00 +0000

Type Values Removed Values Added
Description The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executable for the BCS service, malicious programs can be executed.
Title Insecure service configuration – unquoted path
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: bizerba

Published:

Updated: 2025-10-31T18:17:20.171Z

Reserved: 2025-10-30T14:08:49.409Z

Link: CVE-2025-12507

cve-icon Vulnrichment

Updated: 2025-10-31T18:17:13.816Z

cve-icon NVD

Status : Received

Published: 2025-10-31T16:15:39.447

Modified: 2025-10-31T16:15:39.447

Link: CVE-2025-12507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.