Description
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.
Problem types
Product status
Any version
Credits
Alex Williams of Pellera Technologies reported this vulnerability to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-310-01
github.com/...p/csaf_files/OT/white/2025/icsa-25-310-01.json