Description
There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validation in the file selection process. This could lead to data integrity issues and unauthorized access by an authenticated privileged user.
References (1)
Core 1
Core References
Scores
CVSS v3
6.6
EPSS
0.0003
EPSS Percentile
8.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-434
Status
published
Products (1)
Bizerba SE & Co. KG/GT-SoftControl
0.0 - 6.0
Published
Mar 26, 2025
Tracked Since
Feb 18, 2026