CVE-2025-53947
7.7Cognex · In-Sight Series and In-Sight Explorer
A local privilege escalation vulnerability exists in Cognex In-Sight products where a data folder with weak permissions allows low-privileged users to corrupt sensitive system data.
Executive summary
Cognex In-Sight products are vulnerable to local data corruption due to insecure folder permissions, posing a risk of system instability or unauthorized data modification.
Vulnerability
This vulnerability, categorized as CWE-276 (Incorrect Default Permissions), occurs because a data folder is created with overly permissive access rights. An attacker with low-level local privileges on the Windows host can modify the contents of this directory.
Business impact
The ability for a local user to corrupt sensitive data can lead to significant operational disruption, loss of system integrity, and potential downtime for industrial automation processes. With a CVSS score of 7.7, this vulnerability is classified as High severity, reflecting the high impact on data integrity and availability despite the requirement for local access.
Remediation
Immediate Action: Apply the vendor-provided security updates as soon as they become available to correct the file system permissions.
Proactive Monitoring: Audit local file system logs for unauthorized access or modifications to the Cognex installation directories.
Compensating Controls: Restrict local user access to the host machine and ensure that only authorized personnel have interactive login capabilities on systems running Cognex software.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the High severity of this vulnerability, administrators should prioritize updating the affected Cognex In-Sight software once a patch is released. In the interim, enforce the principle of least privilege by strictly limiting the number of local users with access to the Windows workstations hosting these applications to mitigate the risk of unauthorized data corruption.
More Cognex CVEs
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written
Sources
Originally found and disclosed by Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA., per the CVE Program record.