CVE-2025-0694Path Traversal in Control FOR Beaglebone SL

CWE-22Path Traversal3 documents3 sources
Severity
6.6MEDIUMNVD
EPSS
0.1%
top 72.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18

Description

Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 0.7 | Impact: 5.9

Affected Packages15 packages

CVEListV5codesys/codesys_control_rte< 3.5.21.0
CVEListV5codesys/codesys_control_win< 3.5.21.0
CVEListV5codesys/codesys_control_rte_sl< 3.5.21.0

🔴Vulnerability Details

2
CVEList
CODESYS Control V3 removable media path traversal2025-03-18
GHSA
GHSA-g55g-4c57-8ccx: Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access2025-03-18
CVE-2025-0694 — Path Traversal | cvebase