Description

The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Linux system. This could allow the attacker to achieve remote command execution, full shell access, and potential lateral movement within the network.

INFO

Published Date :

2025-10-23T19:49:23.232Z

Last Modified :

2025-10-23T20:29:27.332Z

Source :

icscert
AFFECTED PRODUCTS

The following products are affected by CVE-2025-58428 vulnerability.

Vendors Products
Veeder
  • Tls4b Automatic Tank Gauge System

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact