{"id":11450,"date":"2025-04-09T16:05:49","date_gmt":"2025-04-09T14:05:49","guid":{"rendered":"https:\/\/limessecurity.ninja\/?p=11450"},"modified":"2026-03-02T21:07:14","modified_gmt":"2026-03-02T20:07:14","slug":"securing-critical-infrastructure-vulnerabilities-in-valmet-dna-cve-2025-0416-cve-2025-0417-cve-2025-0418","status":"publish","type":"post","link":"https:\/\/limessecurity.com\/de\/securing-critical-infrastructure-vulnerabilities-in-valmet-dna-cve-2025-0416-cve-2025-0417-cve-2025-0418\/","title":{"rendered":"Securing Critical Infrastructure: Vulnerabilities in Valmet DNA (CVE-2025-0416, CVE-2025-0417, CVE-2025-0418)"},"content":{"rendered":"[vc_row type=&#8220;full_width_content&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; equal_height=&#8220;yes&#8220; content_placement=&#8220;top&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; constrain_group_1=&#8220;yes&#8220; left_padding_desktop=&#8220;0&#8243; constrain_group_2=&#8220;yes&#8220; right_padding_desktop=&#8220;0&#8243; left_padding_phone=&#8220;14px&#8220; constrain_group_6=&#8220;yes&#8220; right_padding_phone=&#8220;14px&#8220; bottom_margin=&#8220;2%&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; zindex=&#8220;10&#8243; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; advanced_gradient_angle=&#8220;0&#8243; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220; shape_type=&#8220;&#8220; gradient_type=&#8220;default&#8220;][vc_column top_padding_desktop=&#8220;0&#8243; constrain_group_100=&#8220;yes&#8220; bottom_padding_desktop=&#8220;0&#8243; left_padding_desktop=&#8220;0&#8243; constrain_group_101=&#8220;yes&#8220; right_padding_desktop=&#8220;0&#8243; top_padding_tablet=&#8220;8vw&#8220; constrain_group_102=&#8220;yes&#8220; bottom_padding_tablet=&#8220;8vw&#8220; left_padding_tablet=&#8220;8vw&#8220; constrain_group_103=&#8220;yes&#8220; right_padding_tablet=&#8220;8vw&#8220; bottom_margin=&#8220;2%&#8220; bottom_margin_tablet=&#8220;20&#8243; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;0px&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;15px&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; overflow=&#8220;hidden&#8220; advanced_gradient_angle=&#8220;0&#8243; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_color=&#8220;rgba(10,10,10,0.1)&#8220; column_border_style=&#8220;solid&#8220; gradient_type=&#8220;default&#8220; column_padding_type=&#8220;advanced&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]\n<div>In einer zunehmend vernetzten Industriewelt sind Cybersicherheitsrisiken allgegenw\u00e4rtig \u2013 besonders dann, wenn sie kritische Prozesssteuerungssysteme wie <strong data-start=\"225\" data-end=\"239\">Valmet DNA<\/strong> betreffen. Valmet DNA ist ein weit verbreitetes Automatisierungs- und Kontrollsystem, das insbesondere in der Zellstoff-, Papier- und Energieindustrie eingesetzt wird, um wichtige Produktionsprozesse zu steuern und zu \u00fcberwachen.<\/div>\n<div>\n<p>Im Rahmen eine Penetrationtest der Technologieumgebung hat unser Team spezialisierter OT-Penetrationstester mehrere Schwachstellen aufgedeckt. Konkret wurden drei Schwachstellen (ver\u00f6ffentlicht als <strong data-start=\"831\" data-end=\"848\">CVE-2025-0416<\/strong>, <strong data-start=\"850\" data-end=\"867\">CVE-2025-0417<\/strong> und <strong data-start=\"872\" data-end=\"889\">CVE-2025-0418<\/strong>) identifiziert, die es einem Angreifer erm\u00f6glichen k\u00f6nnten, uneingeschr\u00e4nkten Zugriff zu erlangen, Passw\u00f6rter im Klartext zu lesen oder Privilegien zu erweitern, um die vollst\u00e4ndige Kontrolle \u00fcber das System zu erlangen.<\/p>\n<\/div>\n[\/vc_column_text][\/vc_column][\/vc_row][vc_row type=&#8220;full_width_content&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;5px&#8220; equal_height=&#8220;yes&#8220; content_placement=&#8220;top&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; top_padding=&#8220;2%&#8220; constrain_group_1=&#8220;yes&#8220; bottom_padding=&#8220;2%&#8220; left_padding_desktop=&#8220;0&#8243; constrain_group_2=&#8220;yes&#8220; right_padding_desktop=&#8220;0&#8243; left_padding_phone=&#8220;14px&#8220; constrain_group_6=&#8220;yes&#8220; right_padding_phone=&#8220;14px&#8220; top_margin=&#8220;0&#8243; bottom_margin=&#8220;0&#8243; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; zindex=&#8220;10&#8243; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; advanced_gradient_angle=&#8220;0&#8243; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220; shape_type=&#8220;&#8220; gradient_type=&#8220;default&#8220;][vc_column top_padding_desktop=&#8220;0&#8243; constrain_group_100=&#8220;yes&#8220; bottom_padding_desktop=&#8220;0&#8243; left_padding_desktop=&#8220;0&#8243; constrain_group_101=&#8220;yes&#8220; right_padding_desktop=&#8220;0&#8243; top_padding_tablet=&#8220;8vw&#8220; constrain_group_102=&#8220;yes&#8220; bottom_padding_tablet=&#8220;8vw&#8220; left_padding_tablet=&#8220;8vw&#8220; constrain_group_103=&#8220;yes&#8220; right_padding_tablet=&#8220;8vw&#8220; bottom_margin_tablet=&#8220;20&#8243; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;0px&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;15px&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; overflow=&#8220;hidden&#8220; advanced_gradient_angle=&#8220;0&#8243; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_color=&#8220;rgba(10,10,10,0.1)&#8220; column_border_style=&#8220;solid&#8220; gradient_type=&#8220;default&#8220; column_padding_type=&#8220;advanced&#8220;][image_with_animation image_url=&#8220;7565&#8243; image_size=&#8220;full&#8220; max_width=&#8220;100%&#8220; max_width_mobile=&#8220;default&#8220; animation_type=&#8220;entrance&#8220; animation=&#8220;None&#8220; animation_movement_type=&#8220;transform_y&#8220; hover_animation=&#8220;none&#8220; alignment=&#8220;&#8220; border_radius=&#8220;none&#8220; box_shadow=&#8220;none&#8220; image_loading=&#8220;default&#8220;][divider line_type=&#8220;No Line&#8220; custom_height=&#8220;10&#8243;][\/vc_column][\/vc_row][vc_row type=&#8220;full_width_content&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; equal_height=&#8220;yes&#8220; content_placement=&#8220;top&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; constrain_group_1=&#8220;yes&#8220; left_padding_desktop=&#8220;0&#8243; constrain_group_2=&#8220;yes&#8220; right_padding_desktop=&#8220;0&#8243; left_padding_phone=&#8220;14px&#8220; constrain_group_6=&#8220;yes&#8220; right_padding_phone=&#8220;14px&#8220; bottom_margin=&#8220;2%&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; zindex=&#8220;10&#8243; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; advanced_gradient_angle=&#8220;0&#8243; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220; shape_type=&#8220;&#8220; gradient_type=&#8220;default&#8220;][vc_column top_padding_desktop=&#8220;0&#8243; constrain_group_100=&#8220;yes&#8220; bottom_padding_desktop=&#8220;0&#8243; left_padding_desktop=&#8220;0&#8243; constrain_group_101=&#8220;yes&#8220; right_padding_desktop=&#8220;0&#8243; top_padding_tablet=&#8220;8vw&#8220; constrain_group_102=&#8220;yes&#8220; bottom_padding_tablet=&#8220;8vw&#8220; left_padding_tablet=&#8220;8vw&#8220; constrain_group_103=&#8220;yes&#8220; right_padding_tablet=&#8220;8vw&#8220; bottom_margin=&#8220;2%&#8220; bottom_margin_tablet=&#8220;20&#8243; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;0px&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;15px&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; overflow=&#8220;hidden&#8220; advanced_gradient_angle=&#8220;0&#8243; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_color=&#8220;rgba(10,10,10,0.1)&#8220; column_border_style=&#8220;solid&#8220; gradient_type=&#8220;default&#8220; column_padding_type=&#8220;advanced&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]\n<div>\n<p>Dieser erfolgreiche Test unterstreicht sowohl den Wert proaktiver Sicherheitstests als auch die Kompetenz von Limes Security bei Penetrationstests f\u00fcr industrielle Steuerungssysteme. Die gefundenen Schwachstellen stellten ein echtes Risiko f\u00fcr die Betriebskontinuit\u00e4t, die Datenintegrit\u00e4t und die Systemsicherheit dar. Dieser Beitrag berichtet \u00fcber unsere Ergebnisse, ihre m\u00f6glichen Auswirkungen und wie unser gemeinschaftlicher Ansatz zur Offenlegung dazu beigetragen hat, kritische Infrastrukturen f\u00fcr alle Valmet DNA Nutzer weltweit zu sichern.<\/p>\n<\/div>\n[\/vc_column_text][\/vc_column][\/vc_row][vc_row type=&#8220;in_container&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; top_padding=&#8220;1%&#8220; bottom_padding=&#8220;1%&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220; gradient_type=&#8220;default&#8220; shape_type=&#8220;&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][vc_custom_heading text=&#8220;Mangelnder Schutz gegen Brute-Force-Angriffe&#8220; font_container=&#8220;tag:h3|text_align:left|line_height:50px&#8220; use_theme_fonts=&#8220;yes&#8220; css=&#8220;&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]\u00dcber die Benutzeroberfl\u00e4che von Valmet DNA kann eine beliebige Anzahl von Anmeldeversuchen unternommen werden, ohne dass der Benutzer gesperrt wird.[\/vc_column_text][divider line_type=&#8220;No Line&#8220;][vc_row_inner equal_height=&#8220;yes&#8220; content_placement=&#8220;top&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;center&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; top_margin=&#8220;0&#8243; constrain_group_1=&#8220;yes&#8220; bottom_margin=&#8220;0&#8243; left_margin=&#8220;0&#8243; constrain_group_2=&#8220;yes&#8220; right_margin=&#8220;0&#8243; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_pie value=&#8220;70&#8243; label_value=&#8220;7.0&#8243; color=&#8220;#9e1510&#8243; css=&#8220;.vc_custom_1743575036377{background-position: center !important;background-repeat: no-repeat !important;background-size: cover !important;}&#8220; el_id=&#8220;orangePieChart&#8220; title=&#8220;CVSS v4.0 Score&#8220; units=&#8220;\/high&#8220;][\/vc_column_inner][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; centered_text=&#8220;true&#8220; desktop_text_alignment=&#8220;left&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;2\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][nectar_icon_list color=&#8220;default&#8220; direction=&#8220;vertical&#8220; icon_size=&#8220;small&#8220; icon_style=&#8220;border&#8220;][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1772482024472-3&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Produkt:&#8220; text=&#8220;Valmet DNA&#8220; tab_id=&#8220;1772482024472-0&#8243;][\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1772482024484-1&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Betroffene Version:&#8220; text=&#8220;All Valmet DNA Operate versions&#8220; tab_id=&#8220;1772482024484-5&#8243;][\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;html&#8220; title=&#8220;List Item&#8220; id=&#8220;1772482024489-3&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;CVE \/ Vendor ID:&#8220; tab_id=&#8220;1772482024489-0&#8243;]\n<p class=\"page-heading\"><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-0417\" target=\"_blank\" rel=\"noopener\">CVE-2025-0417<\/a><\/p>\n[\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1772482024497-2&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Gefunden von&#8220; text=&#8220;Felix Eberstaller &amp; Sixtus Leonhardsberger&#8220; tab_id=&#8220;1772482024497-6&#8243;][\/nectar_icon_list_item][\/nectar_icon_list][\/vc_column_inner][\/vc_row_inner][nectar_btn size=&#8220;small&#8220; button_style=&#8220;regular&#8220; button_color_2=&#8220;Accent-Color&#8220; icon_family=&#8220;none&#8220; text=&#8220;CVSS:4.0\/AV:L\/AC:L\/AT:N\/PR:N\/UI:N\/VC:N\/VI:L\/VA:H\/SC:N\/SI:N\/SA:N\/AU:Y\/R:A\/V:D\/RE:L\/U:Green&#8220; url=&#8220;https:\/\/www.first.org\/cvss\/calculator\/4-0#CVSS:4.0\/AV:L\/AC:L\/AT:N\/PR:N\/UI:N\/VC:N\/VI:L\/VA:H\/SC:N\/SI:N\/SA:N\/AU:Y\/R:A\/V:D\/RE:L\/U:Green&#8220;][\/vc_column][\/vc_row][vc_row type=&#8220;full_width_background&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; bottom_padding=&#8220;2%&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220; shape_type=&#8220;&#8220; gradient_type=&#8220;default&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][tabbed_section style=&#8220;minimal_flexible&#8220; tab_color=&#8220;Accent-Color&#8220; vs_content_animation=&#8220;fade&#8220; vs_link_animation=&#8220;opacity&#8220; vs_navigation_alignment=&#8220;left&#8220; vs_navigation_width_2=&#8220;25%&#8220; vs_navigation_func=&#8220;default&#8220; vs_navigation_width=&#8220;regular&#8220; vs_navigation_spacing=&#8220;15px&#8220; vs_navigation_mobile_display=&#8220;visible&#8220; vs_tab_spacing=&#8220;5%&#8220; icon_size=&#8220;24&#8243;][tab icon_family=&#8220;iconsmind&#8220; title=&#8220;Problem Beschreibung&#8220; id=&#8220;1772482024591-9&#8243; icon_iconsmind=&#8220;iconsmind-Unlock&#8220; tab_id=&#8220;1772482024591-10&#8243;][vc_row_inner column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;left&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;top-bottom&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; enable_animation=&#8220;true&#8220; animation=&#8220;fade-in-from-bottom&#8220; animation_easing=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_column_text css=&#8220;.vc_custom_1744098656808{padding-right: 10% !important;}&#8220; text_direction=&#8220;default&#8220;]Die betroffene Anwendung bereinigt Eingabedaten nicht ordnungsgem\u00e4\u00df, bevor sie an den SQL-Server gesendet werden. Dies k\u00f6nnte es einem Angreifer mit Zugriff auf die Anwendung erm\u00f6glichen, diese Schwachstelle auszunutzen, um b\u00f6sartige SQL-Befehle auszuf\u00fchren und die gesamte Datenbank zu kompromittieren.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/tab][tab icon_family=&#8220;iconsmind&#8220; title=&#8220;Empfohlene Ma\u00dfnahmen&#8220; id=&#8220;1772482024618-4&#8243; icon_iconsmind=&#8220;iconsmind-Idea-2&#8243; tab_id=&#8220;1772482024618-2&#8243;][vc_row_inner equal_height=&#8220;yes&#8220; content_placement=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;right&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;left&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]Eine ordnungsgem\u00e4\u00df konfigurierte Firewall hilft, den unbefugten Zugriff aus nicht vertrauensw\u00fcrdigen Netzen auf das System zu verhindern. Die Betriebsbereitschaft sollte immer nach den besten Praktiken der Branche bewertet werden.<\/p>\n<p>Die neue Version ist \u00fcber den Valmet Automation-Kundendienst erh\u00e4ltlich.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/tab][\/tabbed_section][\/vc_column][\/vc_row][vc_row type=&#8220;in_container&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; top_padding=&#8220;1%&#8220; bottom_padding=&#8220;1%&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220; gradient_type=&#8220;default&#8220; shape_type=&#8220;&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][vc_custom_heading text=&#8220;Benutzerpassw\u00f6rter im Klartext&#8220; font_container=&#8220;tag:h3|text_align:left|line_height:50px&#8220; use_theme_fonts=&#8220;yes&#8220; css=&#8220;&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]Die Passw\u00f6rter von Valmet DNA-Benutzern werden im Klartext in den Valmet DNA-Funktionsbl\u00f6cken gespeichert.[\/vc_column_text][divider line_type=&#8220;No Line&#8220;][vc_row_inner equal_height=&#8220;yes&#8220; content_placement=&#8220;top&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;center&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; top_margin=&#8220;0&#8243; constrain_group_1=&#8220;yes&#8220; bottom_margin=&#8220;0&#8243; left_margin=&#8220;0&#8243; constrain_group_2=&#8220;yes&#8220; right_margin=&#8220;0&#8243; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_pie value=&#8220;89&#8243; label_value=&#8220;8.9&#8243; color=&#8220;#9e1510&#8243; css=&#8220;.vc_custom_1743575392497{background-position: center !important;background-repeat: no-repeat !important;background-size: cover !important;}&#8220; title=&#8220;CVSS v4.0 Score&#8220; units=&#8220;\/high&#8220;][\/vc_column_inner][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; centered_text=&#8220;true&#8220; desktop_text_alignment=&#8220;left&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;2\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][nectar_icon_list color=&#8220;default&#8220; direction=&#8220;vertical&#8220; icon_size=&#8220;small&#8220; icon_style=&#8220;border&#8220;][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1772482024781-3&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Produkt:&#8220; text=&#8220;Valmet DNA&#8220; tab_id=&#8220;1772482024781-7&#8243;][\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1772482024790-9&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Betroffene Version:&#8220; text=&#8220;Valmet DNA Operate versions C2021 and older&#8220; tab_id=&#8220;1772482024790-10&#8243;][\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;html&#8220; title=&#8220;List Item&#8220; id=&#8220;1772482024799-10&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;CVE \/ Vendor ID:&#8220; tab_id=&#8220;1772482024799-9&#8243;]\n<p class=\"page-heading\"><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-0418\" target=\"_blank\" rel=\"noopener\">CVE-2025-0418<\/a><\/p>\n[\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1772482024803-7&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Gefunden von&#8220; text=&#8220;Felix Eberstaller &amp; Sixtus Leonhardsberger&#8220; tab_id=&#8220;1772482024804-2&#8243;][\/nectar_icon_list_item][\/nectar_icon_list][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row type=&#8220;full_width_background&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; bottom_padding=&#8220;2%&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220; shape_type=&#8220;&#8220; gradient_type=&#8220;default&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][nectar_btn size=&#8220;small&#8220; button_style=&#8220;regular&#8220; button_color_2=&#8220;Accent-Color&#8220; icon_family=&#8220;none&#8220; text=&#8220;CVSS:4.0\/AV:L\/AC:L\/AT:N\/PR:N\/UI:N\/VC:N\/VI:L\/VA:H\/SC:N\/SI:N\/SA:N\/AU:Y\/R:A\/V:D\/RE:L\/U:Green&#8220; url=&#8220;https:\/\/www.first.org\/cvss\/calculator\/4-0#CVSS:4.0\/AV:A\/AC:L\/AT:P\/PR:L\/UI:N\/VC:H\/VI:H\/VA:H\/SC:H\/SI:H\/SA:H\/S:N\/AU:Y\/R:U\/V:D\/RE:H\/U:Amber&#8220;][tabbed_section style=&#8220;minimal_flexible&#8220; tab_color=&#8220;Accent-Color&#8220; vs_content_animation=&#8220;fade&#8220; vs_link_animation=&#8220;opacity&#8220; vs_navigation_alignment=&#8220;left&#8220; vs_navigation_width_2=&#8220;25%&#8220; vs_navigation_func=&#8220;default&#8220; vs_navigation_width=&#8220;regular&#8220; vs_navigation_spacing=&#8220;15px&#8220; vs_navigation_mobile_display=&#8220;visible&#8220; vs_tab_spacing=&#8220;5%&#8220; icon_size=&#8220;24&#8243;][tab icon_family=&#8220;iconsmind&#8220; title=&#8220;Problem Beschreibung&#8220; id=&#8220;1772482024906-3&#8243; icon_iconsmind=&#8220;iconsmind-Unlock&#8220; tab_id=&#8220;1772482024907-2&#8243;][vc_row_inner column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;left&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;top-bottom&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; enable_animation=&#8220;true&#8220; animation=&#8220;fade-in-from-bottom&#8220; animation_easing=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_column_text css=&#8220;.vc_custom_1744098867074{padding-right: 10% !important;}&#8220; text_direction=&#8220;default&#8220;]Diese Praxis stellt ein Sicherheitsrisiko dar, da Angreifer, die sich Zugang zu lokalen Projektdaten verschaffen, die Kennw\u00f6rter lesen k\u00f6nnen.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/tab][tab icon_family=&#8220;iconsmind&#8220; title=&#8220;Empfohlene Ma\u00dfnahmen&#8220; id=&#8220;1772482024948-4&#8243; icon_iconsmind=&#8220;iconsmind-Idea-2&#8243; tab_id=&#8220;1772482024948-8&#8243;][vc_row_inner equal_height=&#8220;yes&#8220; content_placement=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;right&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;left&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]Eine richtig konfigurierte Firewall hilft, den unberechtigten Zugriff von nicht vertrauensw\u00fcrdigen Netzwerken auf das System zu verhindern.<br \/>\nDie L\u00f6sung ist beim Valmet Automation-Kundendienst erh\u00e4ltlich.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/tab][\/tabbed_section][\/vc_column][\/vc_row][vc_row type=&#8220;in_container&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; top_padding=&#8220;1%&#8220; bottom_padding=&#8220;1%&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220; gradient_type=&#8220;default&#8220; shape_type=&#8220;&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][vc_custom_heading text=&#8220;Lokale Privilegienerweiterung durch unsichere DCOM-Konfiguration&#8220; font_container=&#8220;tag:h3|text_align:left|line_height:50px&#8220; use_theme_fonts=&#8220;yes&#8220; css=&#8220;&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]It is possible to gain SYSTEM privileges as any local user via a permission issue in the DCOM object.[\/vc_column_text][divider line_type=&#8220;No Line&#8220;][vc_row_inner equal_height=&#8220;yes&#8220; content_placement=&#8220;top&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;center&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; top_margin=&#8220;0&#8243; constrain_group_1=&#8220;yes&#8220; bottom_margin=&#8220;0&#8243; left_margin=&#8220;0&#8243; constrain_group_2=&#8220;yes&#8220; right_margin=&#8220;0&#8243; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_pie value=&#8220;89&#8243; label_value=&#8220;8.9&#8243; color=&#8220;#9e1510&#8243; css=&#8220;.vc_custom_1743575392497{background-position: center !important;background-repeat: no-repeat !important;background-size: cover !important;}&#8220; title=&#8220;CVSS v4.0 Score&#8220; units=&#8220;\/high&#8220;][\/vc_column_inner][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; centered_text=&#8220;true&#8220; desktop_text_alignment=&#8220;left&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;2\/3&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][nectar_icon_list color=&#8220;default&#8220; direction=&#8220;vertical&#8220; icon_size=&#8220;small&#8220; icon_style=&#8220;border&#8220;][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1772482025109-1&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Produkt:&#8220; text=&#8220;Valmet DNA&#8220; tab_id=&#8220;1772482025110-1&#8243;][\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1772482025119-2&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Betroffene Version:&#8220; text=&#8220;Valmet DNA Operate versions C2022 and older&#8220; tab_id=&#8220;1772482025119-7&#8243;][\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;html&#8220; title=&#8220;List Item&#8220; id=&#8220;1772482025129-1&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;CVE \/ Vendor ID:&#8220; tab_id=&#8220;1772482025129-9&#8243;]\n<p class=\"page-heading\"><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-0416\" target=\"_blank\" rel=\"noopener\">CVE-2025-0416<\/a><\/p>\n[\/nectar_icon_list_item][nectar_icon_list_item icon_type=&#8220;icon&#8220; text_full_html=&#8220;simple&#8220; title=&#8220;List Item&#8220; id=&#8220;1772482025138-10&#8243; icon_fontawesome=&#8220;fa fa-thumb-tack&#8220; header=&#8220;Gefunden von&#8220; text=&#8220;Felix Eberstaller &amp; Sixtus Leonhardsberger&#8220; tab_id=&#8220;1772482025138-5&#8243;][\/nectar_icon_list_item][\/nectar_icon_list][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row type=&#8220;full_width_background&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; bottom_padding=&#8220;2%&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220; shape_divider_position=&#8220;bottom&#8220; bg_image_animation=&#8220;none&#8220; shape_type=&#8220;&#8220; gradient_type=&#8220;default&#8220;][vc_column column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; column_position=&#8220;default&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220;][nectar_btn size=&#8220;small&#8220; button_style=&#8220;regular&#8220; button_color_2=&#8220;Accent-Color&#8220; icon_family=&#8220;none&#8220; text=&#8220;CVSS:4.0\/AV:L\/AC:L\/AT:N\/PR:N\/UI:N\/VC:N\/VI:L\/VA:H\/SC:N\/SI:N\/SA:N\/AU:Y\/R:A\/V:D\/RE:L\/U:Green&#8220; url=&#8220;https:\/\/www.first.org\/cvss\/calculator\/4-0#CVSS:4.0\/AV:A\/AC:L\/AT:P\/PR:L\/UI:N\/VC:H\/VI:H\/VA:H\/SC:H\/SI:H\/SA:H\/S:N\/AU:Y\/R:U\/V:D\/RE:H\/U:Amber&#8220;][tabbed_section style=&#8220;minimal_flexible&#8220; tab_color=&#8220;Accent-Color&#8220; vs_content_animation=&#8220;fade&#8220; vs_link_animation=&#8220;opacity&#8220; vs_navigation_alignment=&#8220;left&#8220; vs_navigation_width_2=&#8220;25%&#8220; vs_navigation_func=&#8220;default&#8220; vs_navigation_width=&#8220;regular&#8220; vs_navigation_spacing=&#8220;15px&#8220; vs_navigation_mobile_display=&#8220;visible&#8220; vs_tab_spacing=&#8220;5%&#8220; icon_size=&#8220;24&#8243;][tab icon_family=&#8220;iconsmind&#8220; title=&#8220;Problem Beschreibung&#8220; id=&#8220;1772482025171-6&#8243; icon_iconsmind=&#8220;iconsmind-Unlock&#8220; tab_id=&#8220;1772482025172-1&#8243;][vc_row_inner column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;left&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;top-bottom&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;default&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; enable_animation=&#8220;true&#8220; animation=&#8220;fade-in-from-bottom&#8220; animation_easing=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_column_text css=&#8220;.vc_custom_1744099008886{padding-right: 10% !important;}&#8220; text_direction=&#8220;default&#8220;]Das DCOM-Objekt Valmet DNA Engineering hat die Berechtigung, Befehle als ein Benutzer mit dem SeImpersonatePrivilege-Recht auszuf\u00fchren. Das SeImpersonatePrivilege-Recht ist eine Windows-Berechtigung, die es einem Prozess erm\u00f6glicht, sich als ein anderer Benutzer auszugeben. Ein Angreifer kann diese Schwachstelle ausnutzen, um seine Privilegien zu erweitern und die vollst\u00e4ndige Kontrolle \u00fcber das System zu \u00fcbernehmen.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/tab][tab icon_family=&#8220;iconsmind&#8220; title=&#8220;Empfohlene Ma\u00dfnahmen&#8220; id=&#8220;1772482025198-6&#8243; icon_iconsmind=&#8220;iconsmind-Idea-2&#8243; tab_id=&#8220;1772482025199-7&#8243;][vc_row_inner equal_height=&#8220;yes&#8220; content_placement=&#8220;middle&#8220; column_margin=&#8220;default&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; text_align=&#8220;right&#8220; row_position=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; pointer_events=&#8220;all&#8220;][vc_column_inner column_padding=&#8220;no-extra-padding&#8220; column_padding_tablet=&#8220;inherit&#8220; column_padding_phone=&#8220;inherit&#8220; column_padding_position=&#8220;all&#8220; flex_gap_desktop=&#8220;10px&#8220; column_element_direction_desktop=&#8220;default&#8220; column_element_spacing=&#8220;default&#8220; desktop_text_alignment=&#8220;left&#8220; tablet_text_alignment=&#8220;default&#8220; phone_text_alignment=&#8220;default&#8220; background_color_opacity=&#8220;1&#8243; background_hover_color_opacity=&#8220;1&#8243; column_backdrop_filter=&#8220;none&#8220; column_shadow=&#8220;none&#8220; column_border_radius=&#8220;none&#8220; column_link_target=&#8220;_self&#8220; overflow=&#8220;visible&#8220; gradient_direction=&#8220;left_to_right&#8220; overlay_strength=&#8220;0.3&#8243; width=&#8220;1\/1&#8243; tablet_width_inherit=&#8220;default&#8220; animation_type=&#8220;default&#8220; bg_image_animation=&#8220;none&#8220; border_type=&#8220;simple&#8220; column_border_width=&#8220;none&#8220; column_border_style=&#8220;solid&#8220; column_padding_type=&#8220;default&#8220; gradient_type=&#8220;default&#8220;][vc_column_text css=&#8220;&#8220; text_direction=&#8220;default&#8220;]Die neue Version von Valmet DNA ist ab sofort \u00fcber den Valmet Automation-Kundendienst erh\u00e4ltlich und sollte sofort implementiert werden.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/tab][\/tabbed_section][\/vc_column][\/vc_row]\n","protected":false},"excerpt":{"rendered":"<p>[vc_row type=&#8220;full_width_content&#8220; full_screen_row_position=&#8220;middle&#8220; column_margin=&#8220;default&#8220; equal_height=&#8220;yes&#8220; content_placement=&#8220;top&#8220; column_direction=&#8220;default&#8220; column_direction_tablet=&#8220;default&#8220; column_direction_phone=&#8220;default&#8220; scene_position=&#8220;center&#8220; constrain_group_1=&#8220;yes&#8220; left_padding_desktop=&#8220;0&#8243; constrain_group_2=&#8220;yes&#8220; right_padding_desktop=&#8220;0&#8243; left_padding_phone=&#8220;14px&#8220; constrain_group_6=&#8220;yes&#8220; right_padding_phone=&#8220;14px&#8220; bottom_margin=&#8220;2%&#8220; text_color=&#8220;dark&#8220; text_align=&#8220;left&#8220; row_border_radius=&#8220;none&#8220; row_border_radius_applies=&#8220;bg&#8220; zindex=&#8220;10&#8243; row_position_desktop=&#8220;default&#8220; row_position_tablet=&#8220;inherit&#8220; row_position_phone=&#8220;inherit&#8220; overflow=&#8220;visible&#8220; advanced_gradient_angle=&#8220;0&#8243; overlay_strength=&#8220;0.3&#8243; gradient_direction=&#8220;left_to_right&#8220;&#8230;<\/p>\n","protected":false},"author":5,"featured_media":11451,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[281],"tags":[],"class_list":{"0":"post-11450","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-advisories"},"_links":{"self":[{"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/posts\/11450","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/comments?post=11450"}],"version-history":[{"count":0,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/posts\/11450\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/media\/11451"}],"wp:attachment":[{"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/media?parent=11450"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/categories?post=11450"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/limessecurity.com\/de\/wp-json\/wp\/v2\/tags?post=11450"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}