CVE-2025-64307
BaseFortify
Publication date: 2025-11-15
Last updated on: 2025-11-15
Assigner: ICS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| brightpick | internal_logic_control | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability is that the Brightpick Internal Logic Control web interface can be accessed without any user authentication. This means an unauthorized user can access and manipulate robot control functions such as starting or stopping runners, assigning jobs, clearing stations, and deploying storage totes.
How can this vulnerability impact me? :
This vulnerability can allow unauthorized users to interfere with robot operations, potentially disrupting automated workflows, causing operational delays, or manipulating job assignments and storage deployments, which could lead to operational inefficiencies or damage.