All the vulnerabilites related to Mechrevo - Control Console
cve-2025-4272
Vulnerability from cvelistv5
Published
2025-05-05 11:00
Modified
2025-05-05 12:32
Severity ?
7.3 (High) - CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
7.0 (High) - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
7.0 (High) - CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
7.0 (High) - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
7.0 (High) - CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS score ?
Summary
Mechrevo Control Console GCUService csCAPI.dll uncontrolled search path
References
▼ | URL | Tags |
---|---|---|
https://vuldb.com/?id.307376 | vdb-entry | |
https://vuldb.com/?ctiid.307376 | signature, permissions-required | |
https://vuldb.com/?submit.563468 | third-party-advisory | |
https://www.yuque.com/ba1ma0-an29k/nnxoap/bhd5ckqugggmpttp?singleDoc | related | |
https://drive.google.com/file/d/1VKhLyW0oglACkt-5PgTtN9oRB2jMczeh/view?usp=sharing | exploit |
Impacted products
▼ | Vendor | Product |
---|---|---|
Mechrevo | Control Console |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-4272", "options": [ { "Exploitation": "poc" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-05-05T12:32:38.631177Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-05-05T12:32:51.133Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "modules": [ "GCUService" ], "product": "Control Console", "vendor": "Mechrevo", "versions": [ { "status": "affected", "version": "1.0.2.70" } ] } ], "credits": [ { "lang": "en", "type": "reporter", "value": "Ba1_Ma0 (VulDB User)" } ], "descriptions": [ { "lang": "en", "value": "A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is some unknown functionality in the library C:\\Program Files\\OEM\\MECHREVO Control Center\\UniwillService\\MyControlCenter\\csCAPI.dll of the component GCUService. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used." }, { "lang": "de", "value": "Eine kritische Schwachstelle wurde in Mechrevo Control Console 1.0.2.70 ausgemacht. Es geht hierbei um eine nicht n\u00e4her spezifizierte Funktion in der Bibliothek C:\\Program Files\\OEM\\MECHREVO Control Center\\UniwillService\\MyControlCenter\\csCAPI.dll der Komponente GCUService. Durch die Manipulation mit unbekannten Daten kann eine uncontrolled search path-Schwachstelle ausgenutzt werden. Der Angriff muss lokal passieren. Die Komplexit\u00e4t eines Angriffs ist eher hoch. Sie ist schwierig ausnutzbar. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung." } ], "metrics": [ { "cvssV4_0": { "baseScore": 7.3, "baseSeverity": "HIGH", "vectorString": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "version": "4.0" } }, { "cvssV3_1": { "baseScore": 7, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "cvssV3_0": { "baseScore": 7, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" } }, { "cvssV2_0": { "baseScore": 6, "vectorString": "AV:L/AC:H/Au:S/C:C/I:C/A:C", "version": "2.0" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-427", "description": "Uncontrolled Search Path", "lang": "en", "type": "CWE" } ] }, { "descriptions": [ { "cweId": "CWE-426", "description": "Untrusted Search Path", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-05-05T11:00:07.406Z", "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB" }, "references": [ { "name": "VDB-307376 | Mechrevo Control Console GCUService csCAPI.dll uncontrolled search path", "tags": [ "vdb-entry" ], "url": "https://vuldb.com/?id.307376" }, { "name": "VDB-307376 | CTI Indicators (IOB, IOC, TTP, IOA)", "tags": [ "signature", "permissions-required" ], "url": "https://vuldb.com/?ctiid.307376" }, { "name": "Submit #563468 | MECHREVO Control Console 1.0.2.70 Elevation Of Privilege", "tags": [ "third-party-advisory" ], "url": "https://vuldb.com/?submit.563468" }, { "tags": [ "related" ], "url": "https://www.yuque.com/ba1ma0-an29k/nnxoap/bhd5ckqugggmpttp?singleDoc" }, { "tags": [ "exploit" ], "url": "https://drive.google.com/file/d/1VKhLyW0oglACkt-5PgTtN9oRB2jMczeh/view?usp=sharing" } ], "timeline": [ { "lang": "en", "time": "2025-05-04T00:00:00.000Z", "value": "Advisory disclosed" }, { "lang": "en", "time": "2025-05-04T02:00:00.000Z", "value": "VulDB entry created" }, { "lang": "en", "time": "2025-05-05T12:56:07.000Z", "value": "VulDB entry last update" } ], "title": "Mechrevo Control Console GCUService csCAPI.dll uncontrolled search path" } }, "cveMetadata": { "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "assignerShortName": "VulDB", "cveId": "CVE-2025-4272", "datePublished": "2025-05-05T11:00:07.406Z", "dateReserved": "2025-05-04T18:28:23.181Z", "dateUpdated": "2025-05-05T12:32:51.133Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }