CVE-2025-6513 Details
Description
Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.
A vulnerability exists in Bizerba BRAIN2 versions prior to 3.06, allowing standard Windows users to access and decrypt the database access configuration file. This issue arises because the file is not adequately secured, enabling unauthorized users to retrieve sensitive database connection information.
Users are advised to update to BRAIN2 version 3.06 or later. For those unable to update, deactivate or delete unnecessary user accounts and ensure that only authorized users have access to the application or device.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2025CISA-ADP
Assessed Jun 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.bizerba.com/downloads/global/information-security/2025/bizerba-sa-2025-0003.pdf | bizerba | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-260 | Password in Configuration File | bizerba |
Affected Products
| Product | Versions |
|---|---|
| Bizerba BRAIN2 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | bizerba |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2025 | New CVE Received | bizerba |
Volerion