An attacker could modify or disable settings, disrupt fuel monitoring
and supply chain operations, leading to disabling of ATG monitoring.
This would result in potential safety hazards in fuel storage and
transportation.
Fixes

Solution

No solution given by the vendor.


Workaround

Lantronix recommends users upgrade to their Xport Edge product, which brings in more cutting edge security suite. Xport edge is not affected by these vulnerabilities. Users should contact Lantronix directly for assistance.

History

Tue, 15 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Description An attacker could modify or disable settings, disrupt fuel monitoring and supply chain operations, leading to disabling of ATG monitoring. This would result in potential safety hazards in fuel storage and transportation.
Title Lantronix Xport Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-15T20:09:58.788Z

Reserved: 2025-03-20T16:56:22.565Z

Link: CVE-2025-2567

cve-icon Vulnrichment

Updated: 2025-04-15T20:09:53.838Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-15T20:15:38.990

Modified: 2025-04-16T13:25:59.640

Link: CVE-2025-2567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.