Description
The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Linux system. This could allow the attacker to achieve remote command execution, full shell access, and potential lateral movement within the network.
Problem types
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
Any version before 11.A
11.A
Credits
Pedro Umbelino of Bitsight reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-296-03
www.veeder.com/us/software-downloads
github.com/...p/csaf_files/OT/white/2025/icsa-25-296-03.json
www.veeder.com/us/network-security-reminder