PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-20002 GMOD CVE debrief

CVE-2025-20002 affects GMOD Apollo and was published on 2025-03-04. According to the CISA advisory, if a user attempts to upload a file that does not meet prerequisites, Apollo can reveal local path information. The issue is rated medium severity (CVSS 5.3) and is addressed by upgrading to Apollo 2.8.0.

Vendor
GMOD
Product
Apollo
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2025-03-04
Original CVE updated
2025-03-04
Advisory published
2025-03-04
Advisory updated
2025-03-04

Who should care

GMOD Apollo administrators, operators, and anyone exposing the application’s file-upload functionality should review this advisory. Security teams responsible for application hardening and disclosure handling should also care, especially where local path details could aid further targeting.

Technical summary

The advisory describes an information disclosure issue in GMOD Apollo versions before 2.8.0. When file upload prerequisites are not met, the application may return local filesystem path information. The provided CVSS vector indicates network attackability, no privileges required, no user interaction, and a limited confidentiality impact (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

Defensive priority

Medium priority. The flaw does not affect integrity or availability, but local path disclosure can still help attackers map deployments or support follow-on attacks. Upgrade planning should be straightforward because a fixed version is identified.

Recommended defensive actions

  • Upgrade GMOD Apollo to version 2.8.0 or later.
  • Review any exposed upload workflows and minimize access to them where possible.
  • Ensure error handling does not reveal filesystem paths or other environment details beyond what is necessary.
  • Use standard ICS/application hardening and defense-in-depth practices for externally reachable services.

Evidence notes

The source corpus is a CISA CSAF advisory for GMOD Apollo (ICSA-25-063-07) published and modified on 2025-03-04. It lists affected product scope as GMOD Apollo <2.8.0, states the issue is a local path information disclosure after failed upload prerequisite checks, and recommends updating to 2.8.0. The advisory does not place this CVE in the Known Exploited Vulnerabilities catalog in the supplied data.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-20002 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-20002

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-20002 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-20002

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-063-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-063-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.