PatchSiren cyber security CVE debrief
CVE-2025-0994 Trimble CVE debrief
CVE-2025-0994 is a Trimble Cityworks deserialization vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-02-07. The authoritative sources supplied here do not provide a CVSS score or deeper technical details, but the KEV listing means defenders should treat it as an urgent remediation item and follow vendor mitigation guidance immediately.
- Vendor
- Trimble
- Product
- Cityworks
- CVSS
- HIGH 7.2
- CISA KEV
- Listed
- Original CVE published
- 2025-02-07
- Original CVE updated
- 2025-02-07
- Advisory published
- 2025-02-07
- Advisory updated
- 2025-02-07
Who should care
Trimble Cityworks administrators, security teams responsible for Cityworks deployments, and incident responders tracking CISA KEV items.
Technical summary
The supplied corpus identifies a deserialization vulnerability in Trimble Cityworks. No CVSS score or exploit mechanics are provided in the supplied sources. CISA's KEV entry confirms known exploitation and directs organizations to apply vendor mitigations or discontinue use of the product if mitigations are unavailable.
Defensive priority
Urgent: CISA KEV-listed and due for remediation by 2025-02-28 according to the supplied timeline.
Recommended defensive actions
- Review the Trimble customer communication and CISA advisory referenced in the source metadata for vendor mitigation steps.
- Apply Trimble-recommended mitigations as soon as possible.
- If mitigations are unavailable or cannot be applied, discontinue use of Cityworks per CISA guidance.
- Inventory all Cityworks instances and confirm which systems are affected.
- Prioritize remediation before the CISA KEV due date of 2025-02-28.
- Monitor official vendor and CISA guidance for updates and verify whether any systems show signs of compromise.
Evidence notes
This debrief is based only on the supplied official and authoritative sources: the CVE record, NVD detail page, CISA KEV catalog entry, and the KEV source feed snapshot. The source corpus confirms the vulnerability name, product, vendor, KEV status, and dates (published/modified 2025-02-07; KEV due date 2025-02-28). It does not supply a CVSS score, exploit chain details, or impact specifics beyond the deserialization classification and known-exploitation status.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-0994 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-0994
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-0994 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-0994
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.