Home

Description

A vulnerability in the web interface of the Güralp Fortimus Series, Minimus Series and Certimus Series allows an unauthenticated attacker with network access to send specially-crafted HTTP requests that can cause the web service process to deliberately restart. Although this mechanism limits the impact of the attack, it results in a brief denial-of-service condition during the restart.

PUBLISHED Reserved 2025-12-10 | Published 2025-12-16 | Updated 2025-12-17 | Assigner icscert




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Problem types

CWE-770 Allocation of Resources Without Limits or Throttling

Product status

Default status
unaffected

All versions
affected

Default status
unaffected

All versions
affected

Default status
unaffected

All versions
affected

Credits

Souvik Kandar finder

References

www.cisa.gov/news-events/ics-advisories/icsa-25-350-01 government-resource

github.com/...p/csaf_files/OT/white/2025/icsa-25-350-01.json

cve.org (CVE-2025-14466)

nvd.nist.gov (CVE-2025-14466)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.