PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-34517 Ilevia CVE debrief

CVE-2025-34517 is a high-severity file-read vulnerability in Ilevia EVE X1 Server firmware. CISA’s advisory says an absolute path traversal issue in get_file_content.php can let an attacker read arbitrary files. The vendor guidance focuses on reducing exposure: do not expose port 8080 to the internet, close it on devices and routers, and use the secure access option in the updated Ilevia Manager.

Vendor
Ilevia
Product
EVE X1
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-05
Original CVE updated
2026-02-05
Advisory published
2026-02-05
Advisory updated
2026-02-05

Who should care

OT/ICS operators using Ilevia EVE X1, plant and building automation teams, network and firewall administrators, and asset owners responsible for any system reachable on port 8080.

Technical summary

The supplied CSAF record describes an absolute path traversal in get_file_content.php on Ilevia EVE X1 Server firmware. The listed CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High), indicating network-reachable access with no privileges or user interaction required and a confidentiality impact from arbitrary file reads. The source also says Ilevia has declined to service the vulnerability and recommends that customers not expose port 8080 to the internet.

Defensive priority

High. Treat as urgent for any internet-exposed deployment or any environment where port 8080 is reachable from untrusted networks.

Recommended defensive actions

  • Identify all Ilevia EVE X1 deployments and confirm whether port 8080 is reachable from the internet or other untrusted networks.
  • Close port 8080 on devices and routers, and block external access at firewalls and edge controls.
  • Upgrade to the newest version of Ilevia Manager from the vendor’s download page and use the secure access option referenced in the advisory.
  • Change all default passwords on active systems to strong, unique credentials.
  • Review firewall rules and network segmentation so only intended management paths are allowed.
  • Monitor for unauthorized access attempts and investigate any unexpected file-access activity or configuration exposure.

Evidence notes

This debrief is based on the CISA CSAF advisory ICSA-26-036-04 and its associated source record, both published on 2026-02-05 with an initial revision history entry on the same date. The source description explicitly states the path traversal in get_file_content.php, the arbitrary file-read impact, the vendor’s decision not to service the issue, and the recommendation not to expose port 8080 to the internet.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-34517 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-34517

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-34517 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-34517

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-036-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-036-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.