← nejvýznamnější zprávy · všechny zprávy

EPSS 0.00

JUMO: Multiple products affected by nodejs vulnerability

[VDE-2026-009] A vulnerability in the REST API of the JUMO device allows an attacker to trigger a denial‑of‑service (DoS) condition. Due to an incorrect implementation of the arrayLimit option in the Node.js qs module, limits for incoming request parameters are not properly enforced. As a result, an attacker can send specially crafted requests containing excessively large or deeply nested arrays, causing the web server to become unresponsive. This condition leads to a crash of the web server,…

Číst originál na CERT@VDE →

CZ · EN/orig

JUMO DE

tg: zranitelnost tp: průmyslové systémy

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2025-15284 6.3 4.0 · harborist 3.7 3.1 · harborist 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.