Description
An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12244 | An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing. |
References
| Link | Providers |
|---|---|
| https://certvde.com/en/advisories/VDE-2025-027 |
|
History
Wed, 23 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Apr 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing. | |
| Title | Forced Browsing Vulnerability in CODESYS Visualization | |
| Weaknesses | CWE-425 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-04-23T16:27:02.990Z
Reserved: 2025-03-21T09:47:52.440Z
Link: CVE-2025-2595
Updated: 2025-04-23T16:26:57.508Z
Status : Awaiting Analysis
Published: 2025-04-23T08:15:14.023
Modified: 2025-04-23T14:08:13.383
Link: CVE-2025-2595
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD