All Advisories / BE-2025-0001

BE-2025-0001

BE-2025-0001: Certificate validation vulnerability in MicroStation via libcurl dependency.

Bentley ID: BE-2025-0001
CVE ID: CVE-2025-5025, CVE-2025-0725, CVE-2024-6197
Severity: 7.4
CVSS: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Publication date: 2025-08-21
Revision date: 2025-08-21

Summary
MicroStation applications may be affected by a certificate validation vulnerability in the libcurl library. The vulnerability occurs when MicroStation uses libcurl for HTTPS transfers with QUIC/HTTP/3 connections and wolfSSL backend. wolfSSL is an SSL implementation targeting embedded systems. It is unlikely that MicroStation operating in a corporate environment would encounter this situation.

Details
MicroStation uses libcurl versions 8.5.0 to 8.14.0 which are affected by improper certificate validation (CWE-295) when using QUIC for HTTP/3 connections with wolfSSL backend. The certificate pinning check that should verify the server’s public key is omitted in this specific configuration within libcurl, potentially allowing MicroStation to unwittingly connect to impostor servers during network operations. While libcurl documentation indicates the option works with wolfSSL, it fails to specify that it does not function properly for QUIC and HTTP/3 connections.

Affected Versions

Applications Affected Versions Mitigated Versions
Bentley MicroStation < = 2024.0.*.* = > 2025.0.0.119

 

Recommended Mitigations
Bentley recommends updating to the latest product version. Best practice is to ensure communications are made over trusted networks and verify server certificates.

Revision History

Date Description
2025-08-21 Initial advisory for CVE-2025-5025, CVE-2025-0725, CVE-2024-6197

20% Off Bentley Software

Deal Ends Friday

Use Coupon Code "THANKS24"