Junglewise Threat Intelligence

CVE-2025-5519: ArgusTech BILGER sensitive information disclosure via message identifiers

CVE-2025-5519 · Severity: medium · CVSS 6.5 · Published 2025-09-16

Technologies: ArgusTech Bilger.

Executive brief

ArgusTech BILGER is susceptible to a security flaw that allows sensitive information to be included in transmitted data. This vulnerability enables an attacker to manipulate message identifiers, potentially leading to unauthorized data exposure or service disruptions. Organizations using BILGER versions prior to 2.4.6 should update to the latest version to protect their communications and operational integrity.

Technical details

A vulnerability classified as CWE-201 (Insertion of Sensitive Information Into Sent Data) exists in ArgusTech BILGER before version 2.4.6. The flaw allows an attacker to choose or manipulate message identifiers, which results in the inclusion of sensitive information within data sent over the network. The attack can be executed remotely without authentication or user interaction. Successful exploitation may lead to a loss of confidentiality and a partial impact on service availability. The issue is addressed in version 2.4.6.

Affected products

  • ArgusTech BILGER before 2.4.6

Timeline

  • 2025-09-16: advisory: Initial publication of the vulnerability advisory
  • 2026-06-05: other: Advisory record modified

References