CVE-2025-2585 HIGH

CVE-2025-2585: EBM Technologies EBM Maintenance Center - SQL injection

Vendor Ebm Technologies
Product EBM Maintenance Center
Weakness CWE-89 · SQLi
Published March 21, 2025
Last update March 21, 2025

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

EBM Maintenance Center From EBM Technologies has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents.

Key dates

02Disclosure timeline

March 21, 2025 CVE published
March 21, 2025 Record updated