Skip to main navigation Skip to main content Skip to page footer

Exposure of the file system

Security Advisories IBA-2025-04

绿色背景带有圆形数字界面设计。
Publishing Date 2025-11-13
Last Update 2026-01-29
Tracking IDIBA-2025-04
CVECVE-2025-14988
CVSS Base Score10
CVSS Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Summary

A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the confidentiality, integrity, or availability of the system.
While there is no evidence of active exploitation, due to the potential severity, we strongly recommend applying the latest update as soon as possible.

Affected products

This applies to all iba products up to the versions listed below:

  • ibaPDA v8.12.0

How do I know that I’m affected?

If you have installed any of the products listed above you are affected.

Mitigation

Steps for ibaPDA if Installing the Update Is Not Possible

  1. Enable User Management:
    To activate user management, go to the User Management settings (found under the Configure option). Set a password for the admin user to enable user management.
  2. Configure Server Access:
    To configure, open Server Access Manager (found under Configure in the ibaPDA Client). Set the configuration so that, for example, only 127.0.0.1 (localhost) or specific system IP addresses that are allowed to communicate with ibaPDA can connect to the ibaPDA Server. (In this example, only connections from localhost are permitted to access ibaPDA.)
  3. Restrict Connections to Localhost (if ibaPDA is only accessed from the system where it runs)
    • Go to I/O Manager → General and deactivate the option “Automatically open necessary ports in Windows Firewall.” (If this option remains active, after a restart of ibaPDA or a restart for data acquisition, the firewall will be reconfigured automatically.)
    • Then go to Advanced Windows Firewall settings and delete or deactivate all incoming rules for the ibaPDA Client and Server.
    • Create manual firewall rules for the connection you use for ibaPDA and verify that you have the correct ports configured. Help regarding which ports the ibaPDA Service uses can be found in the iba Help Center.
    • Imported: After the change, verify that all ibaPDA services are working as expected and that the data acquisition is functioning correctly.

Solution

Please update to the version listed below or a higher one.

  • ibaPDA v8.12.1

Customer actions

Please install the update as described in the solution.

Timeline

2025-10-31Noted by the Security Team
2025-11-13Fix for the problem in ibaPDA v8.12.1
返回列表视图

你今天想做什么?

选择国家后,我的请求将转发给 iba AG 负责销售和支持的国家分支机构。隐私政策