{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-41761","assignerOrgId":"270ccfa6-a436-4e77-922e-914ec3a9685c","state":"PUBLISHED","assignerShortName":"CERTVDE","dateReserved":"2025-04-16T11:18:45.760Z","datePublished":"2026-03-09T08:17:11.116Z","dateUpdated":"2026-03-09T20:14:04.600Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"UBR-01 Mk II","vendor":"MBS","versions":[{"lessThan":"6.0.1.0","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"UBR-02","vendor":"MBS","versions":[{"lessThan":"6.0.1.0","status":"affected","version":"0.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"UBR-LON","vendor":"MBS","versions":[{"lessThan":"6.0.1.0","status":"affected","version":"0.0.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","user":"00000000-0000-4000-9000-000000000000","value":"Adrien Rey from Cyber Defense Campus Zurich"},{"lang":"en","type":"finder","user":"00000000-0000-4000-9000-000000000000","value":"Daniel Hulliger from Armasuisse"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to obtain full system access. This is due to the service account being permitted to execute certain binaries (e.g., tcpdump and ip) with sudo.<br>"}],"value":"A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to obtain full system access. This is due to the service account being permitted to execute certain binaries (e.g., tcpdump and ip) with sudo."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-88","description":"CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"270ccfa6-a436-4e77-922e-914ec3a9685c","shortName":"CERTVDE","dateUpdated":"2026-03-09T08:17:11.116Z"},"references":[{"url":"https://www.mbs-solutions.de/mbs-2025-0001"}],"source":{"defect":["CERT@VDE#641895"],"discovery":"UNKNOWN"},"title":"Privilege escalation possible","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2025-41761","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2026-03-09T20:02:37.352857Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-03-09T20:14:04.600Z"}}]}}