CVE-2025-1265

CRITICAL

Vinci Protocol Analyzer - Command Injection

Title source: llm
STIX 2.1

Description

An OS command injection vulnerability exists in Vinci Protocol Analyzer that could allow an attacker to escalate privileges and perform code execution on affected system.

References (2)

Core 2
Core References
Various Sources
https://elseta.com/support/
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-25-051-06

Scores

CVSS v3 9.9
EPSS 0.0129
EPSS Percentile 66.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
Elseta/Vinci Protocol Analyzer < 3.2.3.19
Published Feb 20, 2025
Tracked Since Feb 18, 2026