The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Linux system. This could allow the attacker to achieve remote command execution, full shell access, and potential lateral movement within the network.
Metrics
Affected Vendors & Products
References
History
Fri, 24 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Veeder
Veeder tls4b Automatic Tank Gauge System |
|
| Vendors & Products |
Veeder
Veeder tls4b Automatic Tank Gauge System |
Thu, 23 Oct 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Linux system. This could allow the attacker to achieve remote command execution, full shell access, and potential lateral movement within the network. | |
| Title | Command Injection in Veeder-Root TLS4B Automatic Tank Gauge System | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published: 2025-10-23T19:49:23.232Z
Updated: 2025-10-23T20:29:27.332Z
Reserved: 2025-09-23T19:56:47.992Z
Link: CVE-2025-58428
No data.
Status : Received
Published: 2025-10-23T20:15:40.443
Modified: 2025-10-23T20:15:40.443
Link: CVE-2025-58428
No data.