Arbitrary File Read Vulnerability in Vitals ESP by Galaxy Software Services
CVE-2025-14253

6.9MEDIUM

Key Information:

Vendor
CVE Published:
8 December 2025

What is CVE-2025-14253?

The Vitals ESP product by Galaxy Software Services is vulnerable to an Arbitrary File Read attack due to Absolute Path Traversal. This allows privileged remote attackers to exploit the vulnerability and download arbitrary system files, potentially compromising sensitive information stored on the server. Organizations using vulnerable versions need to take immediate action to mitigate the risks associated with this security flaw.

Affected Version(s)

Vitals ESP 0 <= 6.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-14253 : Arbitrary File Read Vulnerability in Vitals ESP by Galaxy Software Services