Source |
The Hacker News |
Identifiant |
8647417 |
Date de publication |
2025-02-07 18:22:00 (vue: 2025-02-07 13:08:25) |
Titre |
CISA Warns of Active Exploitation in Trimble Cityworks Vulnerability Leading to IIS RCE |
Texte |
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that a security flaw impacting Trimble Cityworks GIS-centric asset management software has come under active exploitation in the wild.
The vulnerability in question is CVE-2025-0994 (CVSS v4 score: 8.6), a deserialization of untrusted data bug that could permit an attacker to conduct remote code execution.
"This could
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that a security flaw impacting Trimble Cityworks GIS-centric asset management software has come under active exploitation in the wild.
The vulnerability in question is CVE-2025-0994 (CVSS v4 score: 8.6), a deserialization of untrusted data bug that could permit an attacker to conduct remote code execution.
"This could |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
0994 2025 active agency asset attacker bug centric cisa cityworks code come conduct could cve cvss cybersecurity data deserialization execution exploitation flaw gis has iis impacting infrastructure leading management permit question rce remote score: security software trimble under untrusted vulnerability warned warns wild |
Tags |
Vulnerability
|
Stories |
|
Move |
|