← Zuruck zu CVEs
CVE-2025-58428
CRITICAL9.9
Beschreibung
The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Linux system. This could allow the attacker to achieve remote command execution, full shell access, and potential lateral movement within the network.
CVE Details
CVSS v3.1 Bewertung9.9
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht10/23/2025
Zuletzt geandert10/27/2025
Quellenvd
Honeypot-Sichtungen0
Schwachen (CWE)
CWE-77
Referenzen
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-296-03.json(ics-cert@hq.dhs.gov)
https://www.cisa.gov/news-events/ics-advisories/icsa-25-296-03(ics-cert@hq.dhs.gov)
https://www.veeder.com/us/network-security-reminder(ics-cert@hq.dhs.gov)
https://www.veeder.com/us/software-downloads(ics-cert@hq.dhs.gov)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.