CVE 7.5 HIGH

Unauthenticated Local File Disclosure in MPDV Mikrolab MIP 2 / FEDRA 2 / HYDRA X Manufacturing Execution System_CVE-2025-12055

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36Β with Servicepack 8 (week 36/2025), which allows an attacker to read arbitrary files from the Windows operating system. The "Filename" parameter of the public $SCHEMAS$ ressource is vulnerable and can be exploited easily.

Basic Information

ID CVE-2025-12055
Source SEC-VLab
Published Oct 27, 2025 at 06:36
Modified Oct 27, 2025 at 18:33

Affected Product

Vendor MPDV Mikrolab GmbH
Product MIP 2
Version <Maintenance Pack 36 with Servicepack 8, release week 36/2025
Affected Versions MPDV Mikrolab GmbH MIP 2 <Maintenance Pack 36 with Servicepack 8, release week 36/2025
MPDV Mikrolab GmbH FEDRA 2 <Maintenance Pack 36 with Servicepack 8, release week 36/2025
MPDV Mikrolab GmbH HYDRA X <Maintenance Pack 36 with Servicepack 8, release week 36/2025

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.