External Control of File Name or Path in SICAM SIAPP SDK - CVE-2026-25605

 

External Control of File Name or Path in SICAM SIAPP SDK - CVE-2026-25605

Published: March 13, 2026


Vulnerability identifier: #VU124015
CSH Severity: Low
CVSS v4: 5.9 [CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25605
CWE-ID: CWE-73
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to the affected application performs file deletion without properly validating the file path or target. A local attacker can delete files or sockets that the affected process has permission to remove, leading to denial of service (DoS) attack.


Affected software

SICAM SIAPP SDK

How to mitigate CVE-2026-25605

Install updates from vendor's website.

SICAM SIAPP SDK - update to 2.1.7

External References

Related Security Bulletins