PatchSiren cyber security CVE debrief
CVE-2025-58428 Veeder-Root CVE debrief
CVE-2025-58428 affects Veeder-Root’s TLS4B Automatic Tank Gauge System and is rated Critical in the supplied advisory data. CISA’s CSAF states that the system’s SOAP-based interface is exposed through the web services handler, and that a remote attacker with valid credentials may execute system-level commands on the underlying Linux system. The practical impact can include remote command execution, full shell access, and possible lateral movement within the network. Veeder-Root recommends upgrading TLS4B to Version 11.A.
- Vendor
- Veeder-Root
- Product
- TLS4B
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-10-23
- Original CVE updated
- 2025-10-23
- Advisory published
- 2025-10-23
- Advisory updated
- 2025-10-23
Who should care
Operators of Veeder-Root TLS4B deployments, OT/ICS security teams, plant engineers, system integrators, and network administrators responsible for tank gauge systems or adjacent industrial networks should prioritize this issue.
Technical summary
The advisory describes an authenticated remote command execution condition in the TLS4B SOAP-based web services path. The vulnerability is reachable over the network and requires valid credentials, but the impact is severe because successful exploitation can yield system-level command execution on the device’s Linux host. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, reflecting remote access, low attack complexity, and high impact across confidentiality, integrity, and availability.
Defensive priority
Immediate. This is a high-risk OT/ICS exposure with critical impact and a vendor-provided fix. Prioritize patching and access hardening ahead of routine maintenance work.
Recommended defensive actions
- Upgrade Veeder-Root TLS4B to Version 11.A as recommended by the vendor.
- Restrict and review access to the web services handler and SOAP interface, especially credentialed remote access paths.
- Audit all TLS4B accounts and credentials; remove unused accounts and rotate credentials where appropriate.
- Segment the TLS4B and related OT assets from enterprise networks to reduce lateral movement risk.
- Monitor for unexpected command execution, configuration changes, or new network access patterns on affected systems.
- Follow CISA/ICS recommended practices for network security and defense in depth when deploying or connecting the console to a network port.
- Contact Veeder-Root Technical Support at +1.800.323.1799 for deployment-specific guidance if needed.
Evidence notes
All substantive findings here come from the supplied CISA CSAF source item and its included remediation text. The advisory explicitly states that the SOAP-based interface is accessible through the web services handler, that attackers with valid credentials can execute system-level commands on the underlying Linux system, and that the likely outcomes include remote command execution, shell access, and potential lateral movement. The remediation guidance in the source recommends upgrading to Version 11.A. No exploit details, external analysis, or unsupported impact claims were added.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-58428 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-58428
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-58428 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-58428
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-296-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-296-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.