CVE-2025-47698

8.0

Cognex · In-Sight Series and In-Sight Explorer

An unauthenticated adjacent attacker can retrieve user-privileged credentials during the firmware upgrade procedure due to cleartext transmission of sensitive information.

Executive summary

Cognex In-Sight vision systems and software are vulnerable to an unauthorized credential disclosure flaw that occurs during firmware update operations.

Vulnerability

This vulnerability, categorized as CWE-319, involves the cleartext transmission of sensitive credentials during the firmware upgrade process. An adjacent, unauthenticated attacker can intercept these credentials while they are in transit.

Business impact

The exposure of user-privileged credentials poses a significant risk to the confidentiality and integrity of industrial control environments. Because these credentials provide authorized access to vision system settings, an attacker could gain persistent unauthorized control over critical monitoring or inspection processes, potentially leading to operational downtime or unauthorized process manipulation. The CVSS score of 8.0 indicates a high-severity risk that requires immediate prioritization.

Remediation

Immediate Action: Review the official CISA advisory (ICSA-25-261-06) and contact Cognex support to obtain the latest firmware or software updates that address this cleartext transmission issue.

Proactive Monitoring: Monitor network traffic for unusual activity originating from the same broadcast domain as the affected vision systems, particularly during maintenance or update windows.

Compensating Controls: Restrict physical and network access to the management interfaces of Cognex devices to trusted administrators only, and isolate the industrial network from unauthorized segments to prevent adjacent-level access.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for unauthorized access to sensitive operational credentials, administrators must treat this vulnerability with high urgency. Ensure that firmware updates are only performed in secure, isolated environments until a vendor-supplied patch is applied to enforce encrypted transmission of credentials.

More Cognex CVEs

Sources

Originally found and disclosed by Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA., per the CVE Program record.