216.73.216.233

CVE-2025-0994

· Published 07/02/2025 01:00 · Modified 21/12/2025 12:25 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2025-0994 2025-02-06CVE-2025-0994CWE-502[email protected]

Essential information

Published
07/02/2025 01:00
Modified
21/12/2025 12:25
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CVSS
8.8 HIGH (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:H

CVSS metrics

Description

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
trimble / cityworks cpe:2.3:a:trimble:cityworks:*:*:*:*:*:*:*:*
trimble / cityworks cpe:2.3:a:trimble:cityworks:*:*:*:*:*:*:*:*

References