Description
Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.
Published: 2025-06-23
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update to the newest Version 3.06


Vendor Workaround

* Deactivate not needed users or delete them * Ensure that only authorized users have access to the device/software

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-18871 Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.
History

Mon, 23 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Jun 2025 13:00:00 +0000

Type Values Removed Values Added
Description Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.
Title BRAIN2 Configuration file for database access not sufficiently secured
Weaknesses CWE-260
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bizerba

Published:

Updated: 2025-06-23T13:25:56.804Z

Reserved: 2025-06-23T09:36:49.537Z

Link: CVE-2025-6513

cve-icon Vulnrichment

Updated: 2025-06-23T13:25:53.637Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-23T13:15:23.040

Modified: 2025-06-23T20:16:21.633

Link: CVE-2025-6513

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses