Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Contact the vendor for the update.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 15 Jan 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gss
Gss vitalsesp |
|
| CPEs | cpe:2.3:a:gss:vitalsesp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gss
Gss vitalsesp |
Tue, 09 Dec 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Galaxy Software Services Corporation
Galaxy Software Services Corporation vitals Esp |
|
| Vendors & Products |
Galaxy Software Services Corporation
Galaxy Software Services Corporation vitals Esp |
Mon, 08 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Dec 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vitals ESP developed by Galaxy Software Services has an Arbitrary File Read vulnerability, allowing privileged remote attackers to exploit Absolute Path Traversal to download arbitrary system files. | |
| Title | Galaxy Software Services|Vitals ESP - Arbitrary File Read | |
| Weaknesses | CWE-36 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-12-08T14:14:28.725Z
Reserved: 2025-12-08T07:12:20.369Z
Link: CVE-2025-14253
Updated: 2025-12-08T14:14:22.789Z
Status : Analyzed
Published: 2025-12-08T08:15:51.883
Modified: 2026-01-15T01:42:38.810
Link: CVE-2025-14253
No data.
OpenCVE Enrichment
Updated: 2025-12-09T10:26:38Z