« Volver al listado

CVE-2025-2819

Estado: AplazadaMedia (6.6)—

There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validation in the file selection process. This could lead to data integrity issues and unauthorized access by an authenticated privileged user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-2819",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-2819",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-26T15:17:38.843313Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "0beee27a-7d8c-424f-8e46-ac453fa147e6",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.6,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "0beee27a-7d8c-424f-8e46-ac453fa147e6",
      "affectedData": [
        {
          "vendor": "Bizerba SE & Co. KG",
          "product": "GT-SoftControl",
          "versions": [
            {
              "status": "affected",
              "version": "0.0",
              "lessThan": "6.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-03-26T15:16:21.970",
  "references": [
    {
      "url": "https://www.bizerba.com/downloads/global/information-security/2025/bizerba-sa-2025-0001.pdf",
      "source": "0beee27a-7d8c-424f-8e46-ac453fa147e6"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "0beee27a-7d8c-424f-8e46-ac453fa147e6",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validation in the file selection process. This could lead to data integrity issues and unauthorized access by an authenticated privileged user."
    },
    {
      "lang": "es",
      "value": "Existe el riesgo de cargas no autorizadas de archivos en GT-SoftControl y posibles sobrescrituras de archivos debido a una validación insuficiente en el proceso de selección. Esto podría generar problemas de integridad de los datos y acceso no autorizado por parte de un usuario con privilegios autenticados."
    }
  ],
  "lastModified": "2026-06-17T09:07:40.577",
  "sourceIdentifier": "0beee27a-7d8c-424f-8e46-ac453fa147e6"
}