Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.
History

Thu, 16 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Oct 2025 18:00:00 +0000

Type Values Removed Values Added
Description Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.
Title Ilevia EVE X1 Server 4.7.18.0.eden Root Privilege Escalation
Weaknesses CWE-250
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-10-16T19:21:37.052Z

Reserved: 2025-04-15T19:15:22.612Z

Link: CVE-2025-34515

cve-icon Vulnrichment

Updated: 2025-10-16T18:25:37.629Z

cve-icon NVD

Status : Received

Published: 2025-10-16T18:15:35.920

Modified: 2025-10-16T18:15:35.920

Link: CVE-2025-34515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.