Skip to the content.

SicommNet Basec product warning

14 Apr 2025 - DIVD

DIVD researcher Jesse Meijer has identified three critical vulnerabilities in the SicommNet BASEC e-procurement system. These vulnerabilities were discovered on the 14th of December 2021. With these vulnerabilities an attacker can bypass all security measures in the tool and access and alter the database of the tool and all data for any customer of SicommNet BASEC.

Bespite several attempts over the years, neither Jesse Meijer, DIVD CSIRT nor CISA has been able to sollicit a meaningful response of from SicommNet. In line with our CNA policy we are now issuing this product warning.

Product warning

If you are currently using or in the past have used SicommNet BASEC, we urge you to:

Our case file DIVD-2025-00001 contains the full details of the vulnerabilities found.

The vulnerabilities are:


Last modified: 11 Apr 2025 11:56 CEST