CVE-2025-27593: RCE due to Device Driver

9.3 CVSS

Description

The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification checks, leading to code execution on target systems.

Classification

CVE ID: CVE-2025-27593

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Problem Types

CWE-494 Download of Code Without Integrity Check

Affected Products

Vendor: SICK AG

Product: SICK DL100-2xxxxxxx

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 6.75% (scored less or equal to compared to others)

EPSS Date: 2025-04-12 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-27593
https://sick.com/psirt
https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF
https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
https://www.first.org/cvss/calculator/3.1
https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0004.pdf
https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0004.json
https://github.security.telekom.com/2025/03/multiple-vulnerabilities-in-sick-dl100.html

Timeline