CVE-2025-34183
published 2025-09-16CVE-2025-34183: Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to…
PriorityP357high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.66%
46.9th percentile
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential reuse.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ilevia | eve_x1_server_firmware | <= 4.7.18.0 | — |
| ilevia_srl | eve_x1_server | <= 4.7.18.0.eden (Logic version: 6.00) | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Ilevia EVE X1 Server
cisa_ics·2026-02-05·CVSS 7.5
[HIGH] Ilevia EVE X1 Server
ICS Advisory
##
Ilevia EVE X1 Server
Release DateFebruary 05, 2026
Alert CodeICSA-26-036-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary shell commands and the disclosure of sensitive system information.
The following versions of Ilevia EVE X1 Server are affected:
- EVE X1 <=4.7.18.0 (CVE-2025-34185, CVE-2025-34184, CVE-2025-34183, CVE-2025-34186, CVE-2025-34187, CVE-2025-34517, CVE-2025-34518, CVE-2025-34512, CVE-2025-34513)
CVSS
Vendor
Equipment
Vulnerabilities
| v3 9.8
| Ilevia
| Ilevia EVE X1 Server
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutraliz
GHSA
GHSA-8h56-g83q-ffr3: Ilevia EVE X1 Server version ≤ 4
ghsa_unreviewed·2025-09-16
CVE-2025-34183 [CRITICAL] CWE-532 GHSA-8h56-g83q-ffr3: Ilevia EVE X1 Server version ≤ 4
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential reuse.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-16
Published