We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-2595

Forced Browsing Vulnerability in CODESYS Visualization



Description

An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.

Reserved 2025-03-21 | Published 2025-04-23 | Updated 2025-04-23 | Assigner CERTVDE


MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-425: Direct Request ('Forced Browsing')

Product status

Default status
unaffected

0.0.0.0 before 4.8.0.0
affected

Credits

M. Ankith by Honeywell finder

References

certvde.com/en/advisories/VDE-2025-027

cve.org (CVE-2025-2595)

nvd.nist.gov (CVE-2025-2595)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-2595

Support options

Helpdesk Chat, Email, Knowledgebase