The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to bypass chroot restrictions and access the entire file system.
Fixes

Solution

Update firmware to version x64.6.2.213 or later, then reboot PowerStation.


Workaround

No workaround given by the vendor.

History

Tue, 08 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Apr 2025 06:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Tue, 08 Apr 2025 02:45:00 +0000

Type Values Removed Values Added
Description The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to bypass chroot restrictions and access the entire file system.
Title HGiga PowerStation - Chroot Escape
Weaknesses CWE-250
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2025-04-08T14:18:44.692Z

Reserved: 2025-04-07T03:20:20.179Z

Link: CVE-2025-3364

cve-icon Vulnrichment

Updated: 2025-04-08T14:18:40.354Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-08T03:15:16.107

Modified: 2025-04-08T18:13:53.347

Link: CVE-2025-3364

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-06-24T09:44:20Z