CISA published an ICS advisory for CVE-2025-14988, a critical (CVSS 9.8) vulnerability in iba Systems ibaPDA 8.12.0 that could allow an unauthenticated attacker to perform unauthorized actions on the underlying file system under certain conditions. The issue is categorized as CWE-732 (Incorrect Permission Assignment for Critical Resource) and may impact the confidentiality, integrity, and availability of affected OT environments; CISA notes deployment in critical manufacturing and that Siemens reported the vulnerability.
Reporting on the advisory emphasized that ibaPDA is commonly used for industrial data acquisition and process monitoring, making file-system tampering a high-impact risk (e.g., data corruption, theft, or disruption). iba Systems recommends updating to ibaPDA v8.12.1 or later; where immediate patching is not feasible, mitigations focus on hardening access (e.g., enabling/locking down user management and restricting network exposure) and following standard ICS defensive practices such as segmentation, minimizing internet exposure, and using secure remote access methods (e.g., VPNs).

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
iba Systems recommended customers upgrade to ibaPDA 8.12.1 or later to remediate CVE-2025-14988. It also advised interim hardening measures including enabling user management, restricting network access, and manually managing Windows Firewall rules.
CISA released ICS advisory ICSA-26-027-01 describing the critical ibaPDA vulnerability, noting Siemens reported the issue and that no known public exploitation was observed at publication. The advisory recommended standard ICS mitigations such as network isolation and secure remote access.
A critical improper permission vulnerability, tracked as CVE-2025-14988, was identified in ibaPDA 8.12.0. The flaw could allow unauthorized actions on the file system and impact confidentiality, integrity, and availability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.