Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » CISA warns about active operation in Trimble CityWorks vulnerability leading to IIS RCE
Global Security

CISA warns about active operation in Trimble CityWorks vulnerability leading to IIS RCE

AdminBy AdminFebruary 7, 2025No Comments2 Mins Read
Trimble Cityworks Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


07 February 2025Hacker NewsVulnerability / malicious software

Trimble cityworks vulnerability

The US Cybersecurity and infrastructure agencies (CISA) have warned that the lack of security affecting Trimble Urban work Asset management software focused on GIS was actively operating in the wild.

The vulnerability in question is the CVE-2025-0994 (CVSS V4: 8.6), desserization of an unreliable data error that can allow the attacker to conduct the removed code.

“This can allow authentified users to implement the code implementation on the Microsoft Infort Services (IIS) Customer Customer,” Cisa – Note In an advisory order of February 6, 2025.

The disadvantage affects the following versions –

  • CityWorks (all versions up to 15.8.9)
  • CityWorks of Office Companion (all versions up to 23.10)
Cybersecurity

While Trimble released patches to resolve security defect as of January 29, 2025, CISA warns that armed with real attacks.

The company, which is outdated in Colorado, also noted that it received reports of “unauthorized attempts to access the deployment of City City City Works”.

Compromise indicators (poppy) liberated By Trimble indicate that vulnerability is used to give up VshellAmong other unspecified useful loads.

It is currently unknown who is behind the attacks and what is the ultimate goal of the company. Users who work on the affected software versions are recommended to update their instances to the latest version for optimal protection.

Found this article interesting? This article is a contribution to one of our esteemed partners. Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.