← Volver a CVEs
CVE-2025-58428
CRITICAL9.9
Descripcion
The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Linux system. This could allow the attacker to achieve remote command execution, full shell access, and potential lateral movement within the network.
Detalles CVE
Puntuacion CVSS v3.19.9
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado10/23/2025
Ultima modificacion10/27/2025
Fuentenvd
Avistamientos honeypot0
Debilidades (CWE)
CWE-77
Referencias
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-296-03.json(ics-cert@hq.dhs.gov)
https://www.cisa.gov/news-events/ics-advisories/icsa-25-296-03(ics-cert@hq.dhs.gov)
https://www.veeder.com/us/network-security-reminder(ics-cert@hq.dhs.gov)
https://www.veeder.com/us/software-downloads(ics-cert@hq.dhs.gov)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.