Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12244 | An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing. |
| Link | Providers |
|---|---|
| https://certvde.com/en/advisories/VDE-2025-027 |
|
Wed, 23 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Apr 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing. | |
| Title | Forced Browsing Vulnerability in CODESYS Visualization | |
| Weaknesses | CWE-425 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-04-23T16:27:02.990Z
Reserved: 2025-03-21T09:47:52.440Z
Link: CVE-2025-2595
Updated: 2025-04-23T16:26:57.508Z
Status : Deferred
Published: 2025-04-23T08:15:14.023
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-2595
No data.
OpenCVE Enrichment
No data.
EUVD