{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-9229",
        "assignerOrgId": "1b7e193f-2525-49a1-b171-84af8827c9eb",
        "state": "PUBLISHED",
        "assignerShortName": "TRO",
        "dateReserved": "2025-08-20T08:29:15.175Z",
        "datePublished": "2025-08-20T08:36:57.846Z",
        "dateUpdated": "2025-11-05T12:09:23.900Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "MiR Robots",
                    "vendor": "Mobile Industrial Robots",
                    "versions": [
                        {
                            "lessThan": "3.0.0",
                            "status": "affected",
                            "version": "0",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "defaultStatus": "unaffected",
                    "product": "MiR Fleet",
                    "vendor": "Mobile Industrial Robots",
                    "versions": [
                        {
                            "lessThan": "3.0.0",
                            "status": "affected",
                            "version": "0",
                            "versionType": "semver"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "reporter",
                    "value": "Lockheed Martin Red Team"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated attackers to view detailed error information, such as file paths and other data, via access to verbose error pages."
                        }
                    ],
                    "value": "Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated attackers to view detailed error information, such as file paths and other data, via access to verbose error pages."
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-212",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-212 Functionality Misuse"
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "attackComplexity": "LOW",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "NONE",
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "confidentialityImpact": "LOW",
                        "integrityImpact": "NONE",
                        "privilegesRequired": "NONE",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-209",
                            "description": "CWE-209 Generation of Error Message Containing Sensitive Information",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "1b7e193f-2525-49a1-b171-84af8827c9eb",
                "shortName": "TRO",
                "dateUpdated": "2025-11-05T12:09:23.900Z"
            },
            "references": [
                {
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://mobile-industrial-robots.com/security-advisories/information-disclosure"
                },
                {
                    "url": "https://supportportal.mobile-industrial-robots.com/documentation/mir-cybersecurity-guide/mir-cybersecurity-guide/"
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "Update to the newest software version, at least version 3.0.0\n\n\n<br>"
                        }
                    ],
                    "value": "Update to the newest software version, at least version 3.0.0"
                }
            ],
            "source": {
                "advisory": "MSA-17",
                "discovery": "EXTERNAL"
            },
            "title": "Information Disclosure in MiR robots and MiR fleet through verbose error pages",
            "workarounds": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<div>If you cannot immediately update to the recommended version, we recommend the following compensating \nmeasures:</div><div>1. Operate the MiR system in a segmented and secured network with strict firewall rules</div><div>2. Secure user accounts on the MiR system as recommended in the MiR Cybersecurity Guide\n\n\n</div>"
                        }
                    ],
                    "value": "If you cannot immediately update to the recommended version, we recommend the following compensating \nmeasures:\n\n1. Operate the MiR system in a segmented and secured network with strict firewall rules\n\n2. Secure user accounts on the MiR system as recommended in the MiR Cybersecurity Guide"
                }
            ],
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-08-20T15:22:09.195431Z",
                                "id": "CVE-2025-9229",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-08-20T15:22:18.229Z"
                }
            }
        ]
    }
}