CVE-2025-1077
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather). The vulnerability is present in the Product Delivery Service (PDS) component in specific server configurations where the PDS pipeline utilizes the IPDS pipeline with Message Editor Output Filters enabled.
A remote unauthenticated
attacker can exploit this vulnerability to send unauthenticated requests to execute the IPDS pipeline with specially crafted Form Properties, enabling remote execution of arbitrary Python code.
Leer descripción completaMostrar menos
This vulnerability could lead to a full system compromise of the affected server, particularly if Visual Weather services are run under a privileged user account—contrary to the documented installation best practices.
Upgrade to the patched versions 7.3.10 (or higher), 8.6.0 (or higher).
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 9.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.86%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1059Command and Scripting Interpreterexecution90 % - Impacto secundario
T1068Exploitation for Privilege Escalationprivilege escalation70 %
Vector CVSS con AV:N/PR:N permite explotación remota sin autenticación (T1190). La descripción explícita de 'arbitrary Python code execution' y 'full system compromise' indica ejecución de comandos (T1059) y potencial escalada si se ejecuta como usuario privilegiado (T1068).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (4)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-20, CWE-502
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-1077",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-1077",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-02-07T15:53:17.352997Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "incident@nbu.gov.sk",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 9.5,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "incident@nbu.gov.sk",
"affectedData": [
{
"vendor": "IBL Software Engineering",
"product": "Visual Weather",
"versions": [
{
"status": "affected",
"version": "8.2.5"
},
{
"status": "affected",
"version": "7.3.9"
},
{
"status": "affected",
"version": "7.3.6 (Enterprise Build)"
},
{
"status": "affected",
"version": "8.5.2 (Enterprise Build)"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "IBL Software Engineering",
"product": "NAMIS",
"versions": [
{
"status": "affected",
"version": "8.2.5"
},
{
"status": "affected",
"version": "7.3.9"
},
{
"status": "affected",
"version": "7.3.6 (Enterprise Build)"
},
{
"status": "affected",
"version": "8.5.2 (Enterprise Build)"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "IBL Software Engineering",
"product": "Aero Weather",
"versions": [
{
"status": "affected",
"version": "8.2.5"
},
{
"status": "affected",
"version": "7.3.9"
},
{
"status": "affected",
"version": "7.3.6 (Enterprise Build)"
},
{
"status": "affected",
"version": "8.5.2 (Enterprise Build)"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "IBL Software Engineering",
"product": "Satellite Weather",
"versions": [
{
"status": "affected",
"version": "8.2.5"
},
{
"status": "affected",
"version": "7.3.9"
},
{
"status": "affected",
"version": "7.3.6 (Enterprise Build)"
},
{
"status": "affected",
"version": "8.5.2 (Enterprise Build)"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-02-07T09:15:08.380",
"references": [
{
"url": "https://www.iblsoft.com/security/advisory-isec-2024-001/",
"source": "incident@nbu.gov.sk"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "incident@nbu.gov.sk",
"description": [
{
"lang": "en",
"value": "CWE-20"
},
{
"lang": "en",
"value": "CWE-502"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather). The vulnerability is present in the Product Delivery Service (PDS) component in specific server configurations where the PDS pipeline utilizes the IPDS pipeline with Message Editor Output Filters enabled.\n\nA remote unauthenticated\n\nattacker can exploit this vulnerability to send unauthenticated requests to execute the IPDS pipeline with specially crafted Form Properties, enabling remote execution of arbitrary Python code. This vulnerability could lead to a full system compromise of the affected server, particularly if Visual Weather services are run under a privileged user account—contrary to the documented installation best practices.\n\n\n\nUpgrade to the patched versions 7.3.10 (or higher), 8.6.0 (or higher)."
},
{
"lang": "es",
"value": "Se ha identificado una vulnerabilidad de seguridad en Visual Weather de IBL Software Engineering y productos derivados (NAMIS, Aero Weather, Satellite Weather). La vulnerabilidad está presente en el componente Product Delivery Service (PDS) en configuraciones de servidor específicas donde la canalización PDS utiliza la canalización IPDS con filtros de salida del editor de mensajes habilitados. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para enviar solicitudes no autenticadas para ejecutar la canalización IPDS con propiedades de formulario especialmente manipuladas, lo que permite la ejecución remota de código Python arbitrario. Esta vulnerabilidad podría provocar un compromiso total del sistema del servidor afectado, en particular si los servicios de Visual Weather se ejecutan bajo una cuenta de usuario privilegiada, lo que contradice las prácticas recomendadas de instalación documentadas. Actualice a las versiones parcheadas 7.3.10 (o superior), 8.6.0 (o superior)."
}
],
"lastModified": "2026-06-17T08:38:20.680",
"sourceIdentifier": "incident@nbu.gov.sk"
}