CVE-2025-64309
8.6Brightpick · Mission Control
Brightpick Mission Control discloses sensitive device telemetry, configuration, and credential information via WebSocket traffic to unauthenticated users.
Executive summary
A high-severity information disclosure vulnerability in Brightpick Mission Control allows unauthenticated attackers to remotely access sensitive system credentials and configuration data.
Vulnerability
The vulnerability involves improper information exposure via WebSocket traffic (CWE-523), where unauthenticated users can access sensitive telemetry and credentials by connecting to a specific, discoverable URL. This flaw allows an attacker with network access to bypass authentication and retrieve critical operational data.
Business impact
The exposure of system credentials and configuration details presents a severe risk to operational continuity and security. An attacker could leverage this information to gain unauthorized administrative access to the broader industrial control environment, potentially leading to system compromise or physical process disruption. Given the CVSS score of 8.6, this vulnerability represents a significant threat to organizational data integrity and infrastructure stability.
Remediation
Immediate Action: Update Brightpick Mission Control to release 1.67.0 or later immediately to resolve the identified information disclosure flaw.
Proactive Monitoring: Review WebSocket traffic logs for unauthorized connections and monitor for unusual network scanning activity targeting known Mission Control endpoints.
Compensating Controls: Implement network segmentation to restrict access to the Mission Control interface and utilize a Web Application Firewall to block unauthorized WebSocket connection attempts to the vulnerable URL.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The sensitivity of the exposed information necessitates immediate attention from security teams. Organizations should prioritize patching to version 1.67.0 to eliminate the exposure path. Until patching is complete, ensure that access to the affected interface is strictly limited to authorized personnel via secure network segments or VPNs to mitigate the risk of unauthorized discovery and access.
Sources
Originally found and disclosed by Souvik Kandar reported these vulnerabilities to CISA., per the CVE Program record.