CVE-2025-55034 Details
Description
General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login.
A vulnerability exists in General Industrial Controls Lynx+ Gateway due to weak password requirements. This flaw may enable an attacker to perform a brute-force attack, leading to unauthorized access and login. Additionally, the gateway is susceptible to cleartext transmission of sensitive information, including plaintext credentials, which could be intercepted by an attacker.
General Industrial Controls (GIC) did not respond to CISA's attempts to coordinate. Users of General Industrial Controls Lynx+ Gateway are encouraged to reach out to GIC for more information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 15, 2025CISA-ADP
Assessed Nov 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-317-08.json | [email protected] | BundleTechnical Description |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-317-08 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-521 | Weak Password Requirements | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| General Industrial Controls Lynx+ Gateway | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 15, 2025 | New CVE Received | [email protected] |
Volerion