CVE-2025-27127

A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project-Server V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions), Totally Integrated Automation Portal (TIA Portal) V20 (All versions < V20 Update 3). The affected application improperly handles uploaded projects in the document root. This could allow an attacker with contributor privileges to cause denial of service by uploading a malicious project.
Configurations

No configuration.

History

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en TIA Project-Server (todas las versiones anteriores a V2.1.1), TIA Project-Server V17 (todas las versiones), Totally Integrated Automation Portal (TIA Portal) V17 (todas las versiones), Totally Integrated Automation Portal (TIA Portal) V18 (todas las versiones), Totally Integrated Automation Portal (TIA Portal) V19 (todas las versiones) y Totally Integrated Automation Portal (TIA Portal) V20 (todas las versiones anteriores a V20 Update 3). La aplicación afectada gestiona incorrectamente los proyectos cargados en la raíz del documento. Esto podría permitir que un atacante con privilegios de colaborador provoque una denegación de servicio al cargar un proyecto malicioso.

08 Jul 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-08 11:15

Updated : 2025-07-08 16:18


NVD link : CVE-2025-27127

Mitre link : CVE-2025-27127

CVE.ORG link : CVE-2025-27127


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type