CVE-2025-27846
BaseFortify
Publication date: 2025-08-14
Last updated on: 2025-08-15
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| espec | north_america_web_controller | 3 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in ESPEC North America Web Controller versions before 3.3.8, where an attacker with physical access can gain elevated privileges because the GRUB bootloader and BIOS are not protected.
How can this vulnerability impact me? :
An attacker with physical access could exploit this vulnerability to gain elevated privileges on the affected system, potentially allowing them to bypass security controls and take unauthorized actions.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, ensure that physical access to the ESPEC North America Web Controller devices is restricted. Additionally, update the device firmware to version 3.3.8 or later where the GRUB and BIOS protections are implemented.