Metrics
Affected Vendors & Products
Wed, 12 Feb 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Trimble
Trimble cityworks |
|
CPEs | cpe:2.3:a:trimble:cityworks:*:*:*:*:*:*:*:* | |
Vendors & Products |
Trimble
Trimble cityworks |
|
Metrics |
cvssV3_1
|
Sat, 08 Feb 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
kev
|
Fri, 07 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
ssvc
|
Thu, 06 Feb 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
ssvc
|
Thu, 06 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Trimble Cityworks versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server. | Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server. |
References |
| |
Metrics |
ssvc
|
Thu, 06 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Trimble Cityworks versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server. | |
Weaknesses | CWE-502 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-02-07T23:20:22.886Z
Reserved: 2025-02-03T18:03:05.707Z
Link: CVE-2025-0994

Updated: 2025-02-06T16:21:54.713Z

Status : Analyzed
Published: 2025-02-06T16:15:41.493
Modified: 2025-02-12T19:29:30.383
Link: CVE-2025-0994

No data.