boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-0994

Trimble Cityworks
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .3109   98.2   YES
AFFECTED
  Product                            Versions     Fixed
  Cityworks                          unspecified  —
  Cityworks (with office companion)  unspecified  —
TIMELINE
  Feb 3   Reserved by icscert
  Feb 6   Published (CNA: icscert)
  Feb 7   Added to CISA KEV, remediation due 2025-02-28
CWE-502 · CNA: icscert · CVSS v4.0 · 3 references · KEV due February 28, 2025

Description

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
February 3, 2025ReservedReserved by icscert
February 6, 2025PublishedPublished (CNA: icscert)
February 7, 2025KEV ADDEDAdded to CISA KEV, remediation due 2025-02-28

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
TrimbleCityworks———
TrimbleCityworks (with office companion)———

Weaknesses

CWE-502

References (3)

Related

Authoritative record: CVE-2025-0994 at cve.org

Vendors: trimble

Weaknesses: CWE-502

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-0994 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.