Vulnerability Description
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trimble | Cityworks | < 15.8.9 |
Related Weaknesses (CWE)
References
- https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communicatVendor Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-037-04Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-US Government Resource
FAQ
What is CVE-2025-0994?
CVE-2025-0994 is a vulnerability with a CVSS score of 8.8 (HIGH). Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perf...
How severe is CVE-2025-0994?
CVE-2025-0994 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-0994?
Check the references section above for vendor advisories and patch information. Affected products include: Trimble Cityworks.