CVE-2025-2595
Severity CVSS v4.0:
Pending analysis
Type:
CWE-425
Direct Request ('Forced Browsing')
Publication date:
23/04/2025
Last modified:
23/04/2025
Description
An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM