CVE-2025-66589
Last modified
CVE-2025-66589 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer. This could allow an attacker to disclose information or cause a system crash.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer. This could allow an attacker to disclose information or cause a system crash.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Azeotech | Daqfactory | < 21.1 |
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-03Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-66589?
How severe is CVE-2025-66589?
How do I fix CVE-2025-66589?
Are you affected by CVE-2025-66589?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
