PatchSiren

Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy CVE published 2026-05-22

CVE-2026-25608

CVE-2026-25608 is a vulnerability in STER that uses unencrypted TCP traffic, allowing attackers to conduct Man-In-The-Middle attacks and obtain sensitive data. This issue was fixed in version 9.5. The vulnerability affects STER systems using unencrypted TCP traffic, potentially impacting confidentiality and integrity. Organizations should review their deployments and update to version 9.5 or later. STER s [truncated]

MEDIUM Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy CVE published 2026-05-22

CVE-2026-25607

The CVE record for CVE-2026-25607 was published on 2026-05-22T10:16:17.470Z and has not been modified since then. The NVD entry is currently Deferred. This vulnerability affects users of STER software, particularly those using weak password encoding algorithms. The STER software uses a weak password encoding algorithm, allowing attackers to guess password values by analyzing how passwords with known value [truncated]

HIGH Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy CVE published 2026-05-22

CVE-2026-25606

A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multiple Search Filters allows for SQL Injection attacks. It allows an authenticated attacker to view sensitive data such as data belonging to other users, or any other data that the application itself is able to access. This issue was fixed in version 9.5. The vulnerability has a significant [truncated]