CVE-2025-2595: Forced Browsing Vulnerability in CODESYS Visualization
Published Apr 23, 2025
·Updated
An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.
Affected Software
1 affected component
CODESYS CODESYS Visualization
Event History
Apr 23, 2025
CVE Published
via MITRE·07:54 AM
Data Sourced
via MITRE·07:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-2595?
CVE-2025-2595 has a high severity rating due to the potential for unauthorized access to sensitive visualization files.
2
How do I fix CVE-2025-2595?
To fix CVE-2025-2595, update to the latest version of CODESYS Visualization that addresses this vulnerability.
3
Who is affected by CVE-2025-2595?
Users of CODESYS Visualization software are affected by CVE-2025-2595.
4
What types of attacks are possible with CVE-2025-2595?
CVE-2025-2595 allows an unauthenticated remote attacker to bypass user management and access files.
5
What kind of information can be exposed due to CVE-2025-2595?
CVE-2025-2595 can lead to exposure of visualization template files and static elements.