{"id":"CVE-2025-66589","title":"In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer","summary":"In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer. This could allow an attacker to disclose informa…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","cwe":["CWE-125"],"vendor":"azeotech","product":"daqfactory","affected":["daqfactory < 21.1"],"patched":["daqfactory 21.1"],"published":"2025-12-11","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-66589","references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-03","label":"ics-cert@hq.dhs.gov"}],"tags":["nvd"],"epss":0.00354,"epssPercentile":0.26769,"ingestedAt":"2026-09-30T23:29:32.484Z","slug":"CVE-2025-66589","body":"## Overview\n\nIn AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer. This could allow an attacker to disclose information or cause a system crash.\n\n## Affected\n\n- `daqfactory < 21.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `daqfactory 21.1`","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}