Bizerba SE & Co. KG
First CVE: Mar 26, 2025Active for: 1 year
9
CVEs Published
More CVEs Published than 25% of tracked CNAs
4.5
Avg CVEs / Year
More Avg CVEs / Year than 30% of tracked CNAs
8.1
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Bizerba SE & Co. KG over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 26, 2025
15 months ago
Most Recent CVE
Jul 20, 2026
4 days ago
Top CVEs
All CVEs published by Bizerba SE & Co. KG as a CNA, regardless of affected vendor or product.
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-16247HIGH In _connect.BRAIN versions prior to 5.06,
the application LogPathConfig.exe is executed during setup. During this
process, existing permissions on %ProgramData% are deleted and rep | Jul 20, 2026 | 7.3 | 31 | NO | NO |
CVE-2026-16246HIGH In BRAIN2 versions prior to 3.09, the
application LogPathConfig.exe is executed during setup. As a result, the
Windows group Everyone is granted full control over %ProgramData% ins | Jul 20, 2026 | 7.3 | 31 | NO | NO |
CVE-2025-12507HIGH The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executable for the BCS service, malicious programs can be executed. | Oct 31, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-12509HIGH On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the BRAIN2 server with administrator rights. | Oct 31, 2025 | 8.4 | 27 | NO | NO |
CVE-2025-6512CRITICAL On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administrator rights. | Jun 23, 2025 | 10.0 | 27 | NO | NO |
CVE-2025-12508HIGH When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to the interception of authentication data and compromise confid | Oct 31, 2025 | 8.4 | 26 | NO | NO |
CVE-2025-6513CRITICAL Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it. | Jun 23, 2025 | 9.3 | 22 | NO | NO |
CVE-2025-2820MEDIUM An authenticated attacker can compromise the availability of the device via the network | Mar 26, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-2819MEDIUM There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validation in the file selection process. This could lead to data i | Mar 26, 2025 | 6.6 | 19 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA9 CVEs
22%
56%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (55.6%)
Network4 (44.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (77.8%)
Unknown0 (0.0%)
Required2 (22.2%)
Privileges Required
Low4 (44.4%)
High2 (22.2%)
None3 (33.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Bizerba SE & Co. KG as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Bizerba SE & Co. KG as a CNA — matched by CVE ID, not by organization name.