« Back to list

Valmet

Valmet DNA: vulnerabilities and CVEs

Valmet DNA has 4 published vulnerabilities, 1 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months1
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-15577High (8.7)0.54%—Feb 12, 2026
An unauthenticated attacker can exploit this vulnerability by manipulating URL to achieve arbitrary file read access.This issue affects Valmet DNA Web Tools: C2022 and older.
CVE-2025-0418Medium (5.2)0.15%—Apr 1, 2025
Valmet DNA user passwords in plain text. This practice poses a security risk as attackers who gain access to local project data can read the passwords.
CVE-2025-0416High (8.9)0.21%—Apr 1, 2025
Local privilege escalation through insecure DCOM configuration in Valmet DNA versions prior to C2023. The DCOM object Valmet DNA Engineering has permissions that allow it to run commands as a user with the…
CVE-2021-26726High (8.8)1.1%—Feb 16, 2022
A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System1
  2. T1068 Exploitation for Privilege Escalation1
  3. T1190 Exploit Public-Facing Application1
  4. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Valmet