Veeder-Root TLS4B Integer Overflow or Wraparound (CVE-2025-55067)

high Tenable OT Security Plugin ID 505882

Synopsis

The remote OT asset is affected by a vulnerability.

Description

The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When the system clock reaches January 19, 2038, it resets to December 13, 1901, causing authentication failures and disrupting core system functionalities such as login access, history visibility, and leak detection termination. This vulnerability could allow an attacker to manipulate the system time to trigger a denial of service (DoS) condition, leading to administrative lockout, operational timer failures, and corrupted log entries.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Veeder-Root is aware of the vulnerability and will provide a fix for it. Until a fix is available, users should adhere to the network security best practices provided by Veeder-Root.
Additionally, users should make all efforts to protect the borders of their environment to prevent bad actors from infiltrating and causing this issue.

Contact Veeder-Root Technical Support at +1.800.323.1799 for additional help or questions.

See Also

https://www.cisa.gov/news-events/ics-advisories/icsa-25-296-03

Plugin Details

Severity: High

ID: 505882

File Name: tenable_ot_veederroot_CVE-2025-55067.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 7/28/2026

Updated: 7/28/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

Percentile: 96.51

CVSS v3

Risk Factor: High

Base Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

CVSS v4

Risk Factor: High

Base Score: 7.1

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:veeder-root:tls4b_firmware

Required KB Items: Tenable.ot/VeederRoot

Patch Publication Date: 10/23/2025

Vulnerability Publication Date: 10/23/2025

Reference Information

CVE: CVE-2025-55067

CWE: 190

ICSA: 25-296-03