The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When the system clock reaches January 19, 2038, it resets to December 13, 1901, causing authentication failures and disrupting core system functionalities such as login access, history visibility, and leak detection termination. This vulnerability could allow an attacker to manipulate the system time to trigger a denial of service (DoS) condition, leading to administrative lockout, operational timer failures, and corrupted log entries.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Veeder-Root is aware of the vulnerability and will provide a fix for it. Until a fix is available, users should adhere to the network security best practices https://www.veeder.com/us/network-security-reminder  provided by Veeder-Root. Additionally, users should make all efforts to protect the borders of their environment to prevent bad actors from infiltrating and causing this issue. Veeder-Root advises that their ASCs review and implement these best practices for network security with their users, when installing a new console or setting up a network port. Contact Veeder-Root Technical Support at +1.800.323.1799 for additional help or questions.

History

Thu, 23 Oct 2025 19:45:00 +0000

Type Values Removed Values Added
Description The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When the system clock reaches January 19, 2038, it resets to December 13, 1901, causing authentication failures and disrupting core system functionalities such as login access, history visibility, and leak detection termination. This vulnerability could allow an attacker to manipulate the system time to trigger a denial of service (DoS) condition, leading to administrative lockout, operational timer failures, and corrupted log entries.
Title Integer Overflow or Wraparound in Veeder-Root TLS4B Automatic Tank Gauge System
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-10-23T20:30:20.323Z

Reserved: 2025-09-23T19:56:48.001Z

Link: CVE-2025-55067

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-23T20:15:40.120

Modified: 2025-10-23T20:15:40.120

Link: CVE-2025-55067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.