ID

VAR-202512-0017


CVE

CVE-2025-66587


TITLE

AzeoTech DAQFactory memory corruption vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-30858

DESCRIPTION

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. AzeoTech DAQFactory is a data acquisition and monitoring software developed by AzeoTech, a US-based company, commonly used in industrial automation. AzeoTech DAQFactory contains a memory corruption vulnerability. This vulnerability stems from memory corruption during the parsing of specially crafted .ctl files, which attackers can exploit to execute arbitrary code

Trust: 1.44

sources: NVD: CVE-2025-66587 // CNVD: CNVD-2025-30858

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-30858

AFFECTED PRODUCTS

vendor:azeotechmodel:daqfactory release (buildscope:eqversion:20.72555)

Trust: 0.6

sources: CNVD: CNVD-2025-30858

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2025-30858
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2025-30858
severity: MEDIUM
baseScore: 6.2
vectorString: AV:L/AC:H/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 1.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2025-30858

EXTERNAL IDS

db:NVDid:CVE-2025-66587

Trust: 1.6

db:ICS CERTid:ICSA-25-345-03

Trust: 0.6

db:CNVDid:CNVD-2025-30858

Trust: 0.6

sources: CNVD: CNVD-2025-30858 // NVD: CVE-2025-66587

REFERENCES

url:https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-03

Trust: 0.6

sources: CNVD: CNVD-2025-30858

SOURCES

db:CNVDid:CNVD-2025-30858
db:NVDid:CVE-2025-66587

LAST UPDATE DATE

2026-01-14T23:36:27.196000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-30858date:2025-12-17T00:00:00
db:NVDid:CVE-2025-66587date:2025-12-30T20:16:01.160

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-30858date:2025-12-17T00:00:00
db:NVDid:CVE-2025-66587date:2025-12-11T21:15:57.733