PT-2025-51373 · Advantech · Advantech Susi

Published

2025-12-16

·

Updated

2026-01-07

·

CVE-2025-14252

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech SUSI versions 5.0.24335 and prior
Description An Improper Access Control issue exists in the Advantech SUSI driver (susi.sys). This allows attackers to read and write to arbitrary memory locations, I/O ports, and Model Specific Registers (MSRs). Successful exploitation can lead to privilege escalation, arbitrary code execution, and information disclosure.
Recommendations Update Advantech SUSI to a version later than 5.0.24335.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-14252

Affected Products

Advantech Susi