Home Trust Center Sicherheitswarnungen
trust-center-ico-6.svg

Sicherheitswarnungen

Diese Seite enthält wichtige Informationen zu Sicherheitslücken
, die bestimmte Versionen von Altium 365-Produkten oder -Dienstleistungen betreffen könnten.

Security advisories for 2024

Self signed certificate validation missing - AD

Altium 24.9.0 does not validate the self signed server certificate, including for cloud connections.

Description

Altium 24.9.0 does not validate the self signed server certificate, including for cloud connections. This allows for MITM attacks that can steal sensitive data including authentication credentials or design data.

CVSS: 5.3

Detail of Vulnerability: CVE-2025-27377

Affected Products
  • Product: Altium Designer, AES
  • Affected version: 24.9
  • Mitigated version: 25.2
Recommendations
  • Update to latest version
     
Acknowledgements

Joris Aerts

Revision History
  • Revision: 1.1
  • Date: 04 April 2025
  • Description: Add acknowledgement

XSS in BOM Viewer - AES

BOM Viewer on AES7.0.3 does not sanitize all fields. 

Description

BOM Viewer on AES7.0.3 does not sanitize all fields. Script execution can be achieved by creating a schematic with a javascript payload in the Description field

CVSS: 6.1
Detail of Vulnerability: CVE-2025-27379

Affected Products
  • Product: AES
  • Affected version: 7.0.3
  • Mitigated version: 7.0.6
Recommendations
  • Update to latest version
Acknowledgements

Joris Aerts

Revision History
  • Revision: 1.1
  • Date: 04 April 2025
  • Description: Add acknowledgement

SQL Injection - AES

An inactive configuration allows SQL injection to occur by not activating the latest implementation of SQL parsing logic.

Description

An inactive configuration allows SQL injection to occur by not activating the latest implementation of SQL parsing logic.

CVSS: 8.5
Detail of Vulnerability: CVE-2025-27378

Affected Products
  • Product: AES
  • Affected version: 7.0.3
  • Mitigated version: 7.0.6
Recommendations
  • Update to latest version
Acknowledgements

Joris Aerts

Revision History
  • Revision: 1.1
  • Date: 04 April 2025
  • Description: Add acknowledgement

HTML injection - AES

Altium Enterprise Server is vulnerable to an HTML injection attack that allows the execution of arbitrary javascript.

Description

Stealing Session ID through Project Release.

CVSS: 7.6
Detail of Vulnerability: CVE-2025-27380

Affected Products
  • Product: AES
  • Affected version: 7.0.3
  • Mitigated version: 7.0.6
Recommendations
  • Update to latest version
Acknowledgements

Joris Aerts

Revision History
  • Revision: 1.1
  • Date: 04 April 2025
  • Description: Add acknowledgement