CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary data to be written to protected locations, potentially leading to escalation of privilege, arbitrary file corruption, exposure of application and system information or persistent denial of service when a low-privileged attacker tampers with the installation folder.
History

Mon, 18 Aug 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Schneider-electric
Schneider-electric software Update Utility
Vendors & Products Schneider-electric
Schneider-electric software Update Utility

Mon, 18 Aug 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 18 Aug 2025 07:30:00 +0000

Type Values Removed Values Added
Description CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary data to be written to protected locations, potentially leading to escalation of privilege, arbitrary file corruption, exposure of application and system information or persistent denial of service when a low-privileged attacker tampers with the installation folder.
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published: 2025-08-18T07:22:05.013Z

Updated: 2025-08-18T12:22:22.123Z

Reserved: 2025-05-28T06:06:42.804Z

Link: CVE-2025-5296

cve-icon Vulnrichment

Updated: 2025-08-18T12:22:19.212Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-18T08:15:27.820

Modified: 2025-08-18T20:16:28.750

Link: CVE-2025-5296

cve-icon Redhat

No data.