An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://certvde.com/en/advisories/VDE-2025-045 | 
                     | 
            
History
                    Tue, 01 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 01 Jul 2025 08:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default. | |
| Title | Pilz: Missing Authentication in Node-RED integration | |
| Weaknesses | CWE-306 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: CERTVDE
Published: 2025-07-01T08:10:06.208Z
Updated: 2025-07-01T14:32:08.516Z
Reserved: 2025-04-16T11:17:48.306Z
Link: CVE-2025-41656
Updated: 2025-07-01T14:32:03.656Z
Status : Awaiting Analysis
Published: 2025-07-01T08:15:24.443
Modified: 2025-07-03T15:14:12.767
Link: CVE-2025-41656
No data.