go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Galaxy Software Services|Vitals ESP - 3 Vulnerabilities

TVN ID TVN-202512001
CVE ID CVE-2025-14253, CVE-2025-14254, CVE-2025-14255
CVSS CVE-2025-14253:
4.9 (Medium) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CVE-2025-14254:
6.5 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE-2025-14255:
6.5 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products Vitals ESP version 6.3 and earlier:
CVE-2025-14253, CVE-2025-14254

Vitals ESP version 6.1 and earlier:
CVE-2025-14255
Description CVE-2025-14253:
Vitals ESP has an Arbitrary File Read vulnerability, allowing privileged remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

CVE-2025-14254:
Vitals ESP has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

CVE-2025-14255:
Vitals ESP has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
Solution Contact the vendor for the update.
Credit Linwz(DEVCORE)
Public Date 2025-12-08
Top