CVE-2025-27615

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-27615
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27615.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-27615
Aliases
  • GHSA-qf9w-x9qx-2mq7
Published
2025-03-10T19:15:40Z
Modified
2025-03-11T08:57:22.290587Z
Summary
[none]
Details

umatiGateway is software for connecting OPC Unified Architecture servers with an MQTT broker utilizing JSON messages. The user interface may possibly be publicly accessible with umatiGateway's provided docker-compose file. With this access, the configuration can be viewed and altered. Commit 5d81a3412bc0051754a3095d89a06d6d743f2b16 uses 127.0.0.1:8080:8080 to limit access to the local network. For those who are unable to use this proposed patch, a firewall on Port 8080 may block remote access, but the workaround may not be perfect because Docker may also bypass a firewall by its iptable based rules for port forwarding.

References

Affected packages

Git / github.com/umati/umatigateway

Affected ranges

Type
GIT
Repo
https://github.com/umati/umatigateway
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

beta