{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination ","urls":["https://certvde.com"]}],"aggregate_severity":{"namespace":"https://www.first.org/cvss/v3.1/specification-document","text":"High"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"Weidmueller product ResMa is affected by ASP.NET AJAX vulnerability.\n\nWeidmueller has released a new firmware for the affected product to fix the vulnerability.","title":"Summary"},{"category":"general","text":"As a general security measure, Weidmueller strongly recommends minimizing network exposure of products. Limit access to trusted networks by using appropriate mechanisms. ","title":"General Recommendation"},{"category":"description","text":"The vulnerability can lead to a denial of service due to the application restarting.","title":"Impact"},{"category":"description","text":"Update ResMa to the version 3.7.4","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"psirt@weidmueller.com","name":"Weidmueller Interface GmbH & Co. KG","namespace":"https://www.weidmueller.com"},"references":[{"category":"external","summary":"Weidmueller Security Advisory Board","url":"https://support.weidmueller.com/support-center/popular-resources/security-advisory-board"},{"category":"external","summary":"CERT@VDE Security Advisories for Weidmueller","url":"https://certvde.com/de/advisories/vendor/weidmueller/"},{"category":"self","summary":"VDE-2025-041: Weidmueller: ResMa is affected by a Vulnerability for ASP.NET AJAX - HTML","url":"https://certvde.com/de/advisories/VDE-2025-041"},{"category":"self","summary":"VDE-2025-041: Weidmueller: ResMa is affected by a Vulnerability for ASP.NET AJAX - CSAF","url":"https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-041.json"}],"title":"Weidmueller: ResMa is affected by a Vulnerability for ASP.NET AJAX","tracking":{"aliases":["VDE-2025-041","WMSA-2500006"],"current_release_date":"2025-05-19T09:00:00.000Z","generator":{"date":"2025-05-16T06:46:49.196Z","engine":{"name":"Secvisogram","version":"2.5.25"}},"id":"VDE-2025-041","initial_release_date":"2025-05-19T09:00:00.000Z","revision_history":[{"date":"2025-05-19T09:00:00.000Z","number":"1","summary":"Initial version"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"branches":[{"category":"product_version_range","name":"<3.7.4","product":{"name":"ResMa <3.7.4","product_id":"CSAFPID-51006"}},{"category":"product_version","name":"3.7.4","product":{"name":"ResMa 3.7.4","product_id":"CSAFPID-52007"}}],"category":"product_name","name":"ResMa"}],"category":"product_family","name":"Software"}],"category":"vendor","name":"Weidmueller"}]},"vulnerabilities":[{"cve":"CVE-2025-3600","cwe":{"id":"CWE-400","name":"Uncontrolled Resource Consumption"},"notes":[{"category":"description","text":"In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service.","title":"Description"}],"product_status":{"fixed":["CSAFPID-52007"],"known_affected":["CSAFPID-51006"]},"remediations":[{"category":"vendor_fix","details":"Update to version V3.7.4","product_ids":["CSAFPID-51006"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","environmentalScore":7.5,"environmentalSeverity":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":7.5,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["CSAFPID-51006"]}],"title":"CVE-2025-3600"}]}