← back
CVE-2025-11697

Studio 5000 ® Simulation Interface Local Code Execution

CVSS 8.9 HIGHEPSS 0.1%CWE-200
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.9EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
11 Nov 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot.
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →