Description
There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validation in the file selection process. This could lead to data integrity issues and unauthorized access by an authenticated privileged user.
Published: 2025-03-26
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Update Software to the current version of the corresponding Software.


Vendor Workaround

* Prevent unauthorized physical access to the device * Disable E-Service to prevent remote access

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8214 There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validation in the file selection process. This could lead to data integrity issues and unauthorized access by an authenticated privileged user.
History

Wed, 26 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 15:00:00 +0000

Type Values Removed Values Added
Description There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validation in the file selection process. This could lead to data integrity issues and unauthorized access by an authenticated privileged user.
Title Unrestricted Fileupload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bizerba

Published:

Updated: 2025-03-26T15:17:46.739Z

Reserved: 2025-03-26T14:42:48.119Z

Link: CVE-2025-2819

cve-icon Vulnrichment

Updated: 2025-03-26T15:17:42.564Z

cve-icon NVD

Status : Deferred

Published: 2025-03-26T15:16:21.970

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-2819

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses