A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the confidentiality, integrity, or availability of the system.
Advisories

No advisories yet.

Fixes

Solution

iba Systems recommends users update to ibaPDA v8.12.1 or a later version. If Installing the update is not possible, iba Systems recommends users: * Enable User Management: To activate user management, navigate to User Management settings under the Configure option. Set a password for the admin user to enable user management. Configure Server Access: To configure, open Server Access Manager (found under Configure in the ibaPDA Client). Set the configuration to restrict access. For example, only 127.0.0.1 (localhost) or specific system IP addresses to communicate with ibaPDA can connect to the ibaPDA Server. (In this example, only connections from localhost are permitted to access ibaPDA.) Restrict Connections to Localhost (if ibaPDA is only accessed from the system where it runs): * Go to I/O Manager, then General, and deactivate the option “Automatically open necessary ports in Windows Firewall.” (If this option remains active, after a restart of ibaPDA or a restart for data acquisition, the firewall will be reconfigured automatically.) * Then, go to Advanced Windows Firewall settings and delete or deactivate all incoming rules for the ibaPDA Client and Server. * Manually create firewall rules for the connection used for ibaPDA and verify that the correct ports are configured. For assistance with identifying the ports used by the ibaPDA service can be found in the iba Help Center. * Note: After making the changes, verify that all ibaPDA services are operating as expected and that the data acquisition is functioning correctly.


Workaround

No workaround given by the vendor.

History

Tue, 27 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 27 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Description A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the confidentiality, integrity, or availability of the system.
Title Incorrect Permission Assignment for Critical Resource vulnerability in iba Systems ibaPDA
Weaknesses CWE-732
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-01-27T20:51:36.885Z

Reserved: 2025-12-19T20:07:46.829Z

Link: CVE-2025-14988

cve-icon Vulnrichment

Updated: 2026-01-27T20:33:10.626Z

cve-icon NVD

Status : Received

Published: 2026-01-27T20:16:14.493

Modified: 2026-01-27T20:16:14.493

Link: CVE-2025-14988

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses