CRITICAL🇵🇱 Wersja polska

CVE-2025-6513

CVSS 9.3v3.1pub. 2025-06-23upd. 2026-04-15

Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.

🤖 AI Analysis
How it works

The BRAIN2 application stores database authentication credentials in a configuration file that is accessible to standard (unprivileged) Windows user accounts. A regular user can read this file and then decrypt the passwords or other access credentials contained in it. The error is classified as CWE-260 (Password in Configuration File), indicating improper protection of credentials stored in configuration files.

Impact

An attacker with local access to the system can obtain BRAIN2 application database credentials, leading to unauthorized access to data, modification or deletion, and potentially lateral movement through the infrastructure.

Mitigation & patch

Apply patches available from the vendor in accordance with the references (Bizerba SA-2025-0003 document). Additionally, it is recommended to restrict permissions to the configuration file at the Windows file system level and immediately change compromised database credentials.

Who is affected

Bizerba BRAIN2 application running on Windows — specific versions indicated in vendor references (bizerba.com)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References