PT-2025-51373 · Advantech · Advantech Susi

CVE-2025-14252

·

Published

2025-12-16

·

Updated

2026-01-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech SUSI versions 5.0.24335 and prior
Description An Improper Access Control issue exists in the Advantech SUSI driver (susi.sys). This allows attackers to read and write to arbitrary memory locations, I/O ports, and Model Specific Registers (MSRs). Successful exploitation can lead to privilege escalation, arbitrary code execution, and information disclosure.
Recommendations Update Advantech SUSI to a version later than 5.0.24335.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14252

Affected Products

Advantech Susi