CVE-2025-15682

8.7

TBEA · TBEA TLogger (TBEA Communication Box 3rd Generation)

TBEA TLogger is susceptible to resource exhaustion due to improper allocation limits, allowing unauthenticated attackers to cause a denial of service.

Executive summary

A vulnerability in the TBEA TLogger communication box allows unauthenticated attackers to trigger a denial of service condition through resource exhaustion.

Vulnerability

This vulnerability is caused by a failure to implement resource limits or throttling (CWE-770). An unauthenticated remote attacker can exploit this to consume excessive system resources, leading to a complete service outage.

Business impact

The inability to properly manage resource allocation poses a severe threat to operational continuity, as the device can be rendered unresponsive by an attacker. Given the CVSS score of 8.7, this is a high-severity issue that could lead to significant downtime for critical industrial communication infrastructure.

Remediation

Immediate Action: Contact the vendor for firmware update availability, as no specific patch version is currently identified.

Proactive Monitoring: Monitor system resource utilization and network traffic logs for spikes in requests that may indicate an attempt to overwhelm the device.

Compensating Controls: Implement network-level access control lists to restrict traffic to the TLogger device to trusted management IPs only.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical nature of communication infrastructure, administrators should prioritize restricting network access to the affected TBEA devices. Monitor vendor channels closely for the release of a security update and apply it immediately upon availability.

More TBEA CVEs