Security Advisory

CVE-2025-12055

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-10-27 06:36:36
Last updated 2025-11-03 17:32:04
Assigner SEC-VLab
CVSS score not scored
State PUBLISHED

Description

HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36 with Servicepack 8 (week 36/2025), which allows an attacker to read arbitrary files from the Windows operating system. The "Filename" parameter of the public $SCHEMAS$ ressource is vulnerable and can be exploited easily.