- Description
- A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather). The vulnerability is present in the Product Delivery Service (PDS) component in specific server configurations where the PDS pipeline utilizes the IPDS pipeline with Message Editor Output Filters enabled. A remote unauthenticated attacker can exploit this vulnerability to send unauthenticated requests to execute the IPDS pipeline with specially crafted Form Properties, enabling remote execution of arbitrary Python code. This vulnerability could lead to a full system compromise of the affected server, particularly if Visual Weather services are run under a privileged user account—contrary to the documented installation best practices. Upgrade to the patched versions 7.3.10 (or higher), 8.6.0 (or higher).
- Source
- incident@nbu.gov.sk
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 9.5
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- incident@nbu.gov.sk
- CWE-20
- Hype score
- Not currently trending
🚨 A critical RCE vulnerability (CVE-2025-1077) affects Visual Weather software. With a CVSSv4 score of 9.5, it's crucial for users to update or apply mitigations immediately. ⚠️ #IBLSoftware #WeatherProducts #USA link: https://t.co/A2GYlc1gN2 https://t.co/JG1YNsZeum
@TweetThreatNews
11 Feb 2025
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-1077: CRITICAL] Critical security vulnerability discovered in IBL Software Engineering Visual Weather & related products can lead to remote execution of arbitrary Python code. Upgrade to versions 7.3.10+...#cybersecurity,#vulnerability https://t.co/06BLVELJvb https:
@CveFindCom
7 Feb 2025
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-1077 A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather). The vulnerabi… https://t.co/ZSB5saQUh4
@CVEnew
7 Feb 2025
293 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes