PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-49152 MICROSENS CVE debrief

CVE-2025-49152 is a HIGH-severity authentication/session-control issue in MICROSENS NMP Web+. According to CISA’s advisory, affected versions contain JSON Web Tokens that do not expire, which can allow an attacker to gain access to the system. MICROSENS recommends updating to NMP Web+ 3.3.0 for Windows and Linux.

Vendor
MICROSENS
Product
NMP Web+
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-06-24
Original CVE updated
2025-06-24
Advisory published
2025-06-24
Advisory updated
2025-06-24

Who should care

Organizations running MICROSENS NMP Web+ in operational or industrial environments, especially administrators responsible for authentication, access control, and patch management.

Technical summary

The advisory identifies MICROSENS NMP Web+ <= 3.2.5 as affected. The core problem is that JWTs do not expire, so token validity is not properly time-limited. CISA assigns CVSS v3.1 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N), indicating a network-reachable issue with no privileges or user interaction required and a high integrity impact.

Defensive priority

High. This affects access control and can permit unauthorized system access; patching should be prioritized for exposed or operational deployments.

Recommended defensive actions

  • Update MICROSENS NMP Web+ to version 3.3.0 for Windows and Linux as recommended by the vendor.
  • Inventory all MICROSENS NMP Web+ deployments and confirm whether any instances are running version 3.2.5 or earlier.
  • Review authentication and session-management controls for affected systems, including token handling and administrative access pathways.
  • Restrict network exposure to NMP Web+ management interfaces until remediation is complete.
  • After upgrading, verify that access tokens and sessions follow expected expiration and revocation behavior.

Evidence notes

CISA’s CSAF advisory ICSA-25-175-07, published 2025-06-24, states that MICROSENS NMP Web+ products at version <= 3.2.5 contain JSON Web Tokens (JWT) that do not expire and that this could allow an attacker to gain access to the system. The advisory’s remediation is to update to NMP Web+ version 3.3.0 for Windows and Linux. The supplied CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N with a score of 7.5 (HIGH).

Sources and references

Verified primary and authoritative sources

  • CVE-2025-49152 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-49152

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-49152 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-49152

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-175-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-175-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.