CVE-2025-31354 Details
Description
Subnet Solutions PowerSYSTEM Center's SMTPS notification service can be affected by importing an EC certificate with crafted F2m parameters, which can lead to excessive CPU consumption during the evaluation of the curve parameters.
A vulnerability exists in Subnet Solutions PowerSYSTEM Center (PSC) 2020, all versions through 5.24.x, within the SMTPS notification service. The issue arises when an EC certificate with manipulated F2m parameters is imported, leading to excessive CPU usage as the system evaluates the curve parameters. This vulnerability can cause a denial-of-service condition by overwhelming the CPU.
Users are advised to update PowerSYSTEM Center to the latest versions: PSC 2020 Update 25 or PSC 2024. If an update is not possible, Subnet Solutions recommends disabling the Notification Service, Email Dispatch Service, or the outgoing email server in the Notifications/Settings. Additionally, configure the PowerSYSTEM Center DCS network firewall to only allow connections to an approved and authorized email server, manage administrator access to the PowerSYSTEM Center DCS operating system, and monitor user activity records to ensure compliance with acceptable usage policies. For assistance with updating PSC, contact Subnet Solutions support.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 11, 2025CISA-ADP
Assessed Apr 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-100-08 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Subnet Solutions PowerSYSTEM Center | <= 5.24.x |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 11, 2025 | New CVE Received | [email protected] |
Volerion