Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Feb 28, 2025

CVE-2025-0994

High
EPSS 77.8%CISA KEV
Trimble/Cityworks

Description

Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.

EPSS — Exploit Probability

77.8%

Higher than 99.0% of all CVEs

Required Action

https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-05-docx/0?; https://www.cisa.gov/news-events/ics-advisories/icsa-25-037-04 ; https://nvd.nist.gov/vuln/detail/CVE-2025-0994

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
77.8%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Feb 7, 2025

Added to KEV

Feb 7, 2025

Remediation Due

Feb 28, 2025

Affected Product

Trimble

Cityworks

View all Trimble CVEs