BE-2025-0003: Database processing vulnerability in MicroStation via SQLite dependency.
Bentley ID: BE-2025-0003
CVE ID: CVE-2025-29088
Severity: 7.5
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Publication date: 2025-08-21
Revision date: 2025-08-21
Summary
MicroStation applications may be affected by a database processing vulnerability in the SQLite library. The vulnerability occurs when MicroStation uses SQLite 3.49.0, where certain argument values to sqlite3_db_config can cause denial of service through application crashes due to incorrect memory allocations.
Details
MicroStation uses SQLite version 3.49.0 which is affected by an integer overflow vulnerability (CWE-190) and uncontrolled resource consumption (CWE-400). This could potentially allow attackers to cause denial of service when MicroStation processes database operations through the vulnerable SQLite library.
Affected Versions
| Applications | Affected Versions | Mitigated Versions |
| Bentley MicroStation | < = 2024.0.*.* | = > 2025.0.0.119 |
Recommended Mitigations
Bentley recommends updating to the latest product version. Best practice is to monitor database operations and limit database access to trusted sources.
Revision History
| Date | Description |
| 2025-08-21 | Initial advisory for CVE-2025-29088 |