PatchSiren cyber security CVE debrief
CVE-2025-20002 GMOD CVE debrief
CVE-2025-20002 affects GMOD Apollo and was published on 2025-03-04. According to the CISA advisory, if a user attempts to upload a file that does not meet prerequisites, Apollo can reveal local path information. The issue is rated medium severity (CVSS 5.3) and is addressed by upgrading to Apollo 2.8.0.
- Vendor
- GMOD
- Product
- Apollo
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-03-04
- Original CVE updated
- 2025-03-04
- Advisory published
- 2025-03-04
- Advisory updated
- 2025-03-04
Who should care
GMOD Apollo administrators, operators, and anyone exposing the application’s file-upload functionality should review this advisory. Security teams responsible for application hardening and disclosure handling should also care, especially where local path details could aid further targeting.
Technical summary
The advisory describes an information disclosure issue in GMOD Apollo versions before 2.8.0. When file upload prerequisites are not met, the application may return local filesystem path information. The provided CVSS vector indicates network attackability, no privileges required, no user interaction, and a limited confidentiality impact (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Defensive priority
Medium priority. The flaw does not affect integrity or availability, but local path disclosure can still help attackers map deployments or support follow-on attacks. Upgrade planning should be straightforward because a fixed version is identified.
Recommended defensive actions
- Upgrade GMOD Apollo to version 2.8.0 or later.
- Review any exposed upload workflows and minimize access to them where possible.
- Ensure error handling does not reveal filesystem paths or other environment details beyond what is necessary.
- Use standard ICS/application hardening and defense-in-depth practices for externally reachable services.
Evidence notes
The source corpus is a CISA CSAF advisory for GMOD Apollo (ICSA-25-063-07) published and modified on 2025-03-04. It lists affected product scope as GMOD Apollo <2.8.0, states the issue is a local path information disclosure after failed upload prerequisite checks, and recommends updating to 2.8.0. The advisory does not place this CVE in the Known Exploited Vulnerabilities catalog in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-20002 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-20002
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-20002 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-20002
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-063-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-063-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.