An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://certvde.com/en/advisories/VDE-2025-045 |
|
History
Tue, 01 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Jul 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default. | |
| Title | Pilz: Missing Authentication in Node-RED integration | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published: 2025-07-01T08:10:06.208Z
Updated: 2025-07-01T14:32:08.516Z
Reserved: 2025-04-16T11:17:48.306Z
Link: CVE-2025-41656
Updated: 2025-07-01T14:32:03.656Z
Status : Awaiting Analysis
Published: 2025-07-01T08:15:24.443
Modified: 2025-07-03T15:14:12.767
Link: CVE-2025-41656
No data.