ICSA-25-037-04: Trimble cityworks vulnerability
Affected Software
2 affected componentsFixes available
: Trimble Cityworks<15.8.9
15.8.9
: Trimble Cityworks with office companion<23.10
23.10
Event History
Feb 6, 2025
Advisory Published
05:51 PM
Frequently Asked Questions
1
What is the severity of ICSA-25-037-04?
The severity of ICSA-25-037-04 is rated as high due to potential unauthorized access to sensitive data.
2
How do I fix ICSA-25-037-04?
To fix ICSA-25-037-04, users should apply the security patches provided by Trimble for affected Cityworks software.
3
What vulnerabilities are associated with ICSA-25-037-04?
ICSA-25-037-04 is associated with multiple vulnerabilities that may allow for remote code execution and unauthorized data access.
4
Which versions of Trimble Cityworks are affected by ICSA-25-037-04?
ICSA-25-037-04 affects specific versions of Trimble Cityworks and Trimble Cityworks with Office Companion as noted in the advisory.
5
Is there a workaround for ICSA-25-037-04?
While applying patches is the primary solution, users can implement network segmentation as a temporary workaround until updates are applied.