All Advisories / BE-2025-0003

BE-2025-0003

BE-2025-0003: Database processing vulnerability in MicroStation via SQLite dependency.

Bentley ID: BE-2025-0003
CVE ID: CVE-2025-29088
Severity: 7.5
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Publication date: 2025-08-21
Revision date: 2025-08-21

Summary
MicroStation applications may be affected by a database processing vulnerability in the SQLite library. The vulnerability occurs when MicroStation uses SQLite 3.49.0, where certain argument values to sqlite3_db_config can cause denial of service through application crashes due to incorrect memory allocations.

Details
MicroStation uses SQLite version 3.49.0 which is affected by an integer overflow vulnerability (CWE-190) and uncontrolled resource consumption (CWE-400). This could potentially allow attackers to cause denial of service when MicroStation processes database operations through the vulnerable SQLite library.

Affected Versions

Applications Affected Versions Mitigated Versions
Bentley MicroStation < = 2024.0.*.* = > 2025.0.0.119

 

Recommended Mitigations
Bentley recommends updating to the latest product version. Best practice is to monitor database operations and limit database access to trusted sources.

Revision History

Date Description
2025-08-21 Initial advisory for CVE-2025-29088

20% Off Bentley Software

Deal Ends Friday

Use Coupon Code "THANKS24"