CVE-2025-11498
⚪ Do wiadomości
Luka w System Diagnostics Manager umożliwia zdalne wstrzyknięcie danych do pliku CSV.
CVSS
6.1
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 enabling a remote attacker to inject formula data into a generated CSV file. The exploitation of this vulnerability requires the attacker to create a malicious link. The user would need to click on this link, after which the resulting CSV file addi-tionally needs to be manually opened.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2025-10-14 13:15:36 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 12:10:00 UTC |