PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-66590 AzeoTech CVE debrief

CVE-2025-66590 is a high-severity out-of-bounds write vulnerability in AzeoTech DAQFactory release 20.7 (Build 2555), published by CISA on December 11, 2025, with subsequent modifications through January 12, 2026. The vulnerability allows an attacker to cause the program to write data past the end of an allocated memory buffer, potentially leading to arbitrary code execution or system crash. The CVSS 3.1 score of 7.8 reflects local attack vector, low attack complexity, no privileges required, and user interaction required, with high impacts to confidentiality, integrity, and availability. AzeoTech has released DAQFactory Release 21.1 as a vendor fix. CISA recommends defense-in-depth measures including avoiding documents from untrusted sources, storing .ctl files in admin-writeable folders only, operating in Safe Mode when loading untrusted documents, and applying document editing passwords.

Vendor
AzeoTech
Product
DAQFactory
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2025-12-11
Original CVE updated
2026-10-07
Advisory published
2025-12-11
Advisory updated
2026-10-07

Who should care

Organizations operating AzeoTech DAQFactory in industrial control system environments, particularly those processing untrusted document files or with multi-user access to .ctl configuration files. Asset owners in manufacturing, process control, and building automation sectors using DAQFactory for data acquisition and supervisory control should prioritize patching.

Technical summary

The vulnerability exists in DAQFactory release 20.7 (Build 2555) where an out-of-bounds write condition can be triggered, causing writes beyond allocated buffer boundaries. This memory safety defect may result in arbitrary code execution within the context of the application or cause denial of service through system crash. The attack requires local access and user interaction, suggesting exploitation via malicious document files.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade to DAQFactory Release 21.1 per vendor fix guidance.
  • Avoid opening documents from unknown or untrusted sources.
  • Store .ctl files in directories with admin-only write permissions.
  • Enable Safe Mode when loading documents that have been outside organizational control.
  • Apply document editing passwords to protect document integrity.
  • Review CISA ICS recommended practices for additional defense-in-depth strategies.

Evidence notes

Vendor and product identification derived from CSAF product tree with high confidence. Remediation guidance extracted from CSAF remediations section. CVSS vector confirmed via source references.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-66590 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-66590

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-66590 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66590

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-345-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.