CVE-2025-25598

Incorrect access control in the scheduled tasks console of Inova Logic CUSTOMER MONITOR (CM) v3.1.757.1 allows attackers to escalate privileges via placing a crafted executable into a scheduled task.
Configurations

Configuration 1 (hide)

cpe:2.3:a:inovalogic:customer_monitor:3.1.757.1:*:*:*:*:*:*:*

History

03 Apr 2025, 16:36

Type Values Removed Values Added
CPE cpe:2.3:a:inovalogic:customer_monitor:3.1.757.1:*:*:*:*:*:*:*
References () https://github.com/quriusfox/vulnerability-research/tree/main/CVE-2025-25598 - () https://github.com/quriusfox/vulnerability-research/tree/main/CVE-2025-25598 - Third Party Advisory
First Time Inovalogic
Inovalogic customer Monitor

19 Mar 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) El control de acceso incorrecto en la consola de tareas programadas de Inova Logic CUSTOMER MONITOR (CM) v3.1.757.1 permite a los atacantes escalar privilegios mediante la colocación de un ejecutable manipulado en una tarea programada.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-284

13 Mar 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-13 18:15

Updated : 2025-04-03 16:36


NVD link : CVE-2025-25598

Mitre link : CVE-2025-25598

CVE.ORG link : CVE-2025-25598


JSON object : View

Products Affected

inovalogic

  • customer_monitor
CWE
CWE-284

Improper Access Control