CVE-2025-47149 Details
Description
The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation. If exploited, the product may treat an unauthorized pattern file as an authorized. If the product uses a specially crafted pattern file, information in the server where the product is running may be retrieved, and/or cause a denial of service (DoS) condition.
A vulnerability exists in the 'Anti-Virus & Sandbox' feature of Digital Arts i-FILTER, specifically in versions 10.50R01 to 10.67R02. This vulnerability arises from improper validation of pattern files, which could allow an unauthorized pattern file to be accepted as legitimate. Exploitation of this issue could lead to unauthorized access to information on the server where i-FILTER is running, or cause a denial-of-service condition.
Users are advised to update i-FILTER to version 10.67R03 or later. For more details, refer to the release note available on the Digital Arts Support site (login required).
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 23, 2025CISA-ADP
Assessed May 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.daj.co.jp/support/detail/?page=releasenote_content&division=6&id=1057 | [email protected] | Permission RequiredVendor |
| https://jvn.jp/en/jp/JVN68079883/ | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-348 | Use of Less Trusted Source | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Digital Arts i-FILTER | All versions |
CPE
Remediation
| |
| Digital Arts D-SPA | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 23, 2025 | New CVE Received | [email protected] |
Volerion