Impact
AiSOC versions 5.1.0 through 11.2.0 expose two internal POST endpoints that can be called without authentication. A remote actor can send crafted events with forged tenant identifiers, causing the service to broadcast the payload through WebSocket and Redis Server‑Sent Events channels or to push notifications to legitimate devices. This allows attackers to deliver arbitrary content, potentially including malware or phishing messages, to any channel or device that is subscribed to those streams. The flaw is a CWE‑306 bypass of authentication controls, which means confidentiality and integrity of the communications channel are compromised without the need for active credential compromise.
Affected Systems
Beenuar’s AiSOC product, versions 5.1.0 up to, but not including, 12.0.0. The vulnerability is specific to the realtime service internal endpoints, POST /internal/agent‑event and POST /internal/push.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, but the issue is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. The attack can be carried out over the internal network or over any exposed port that hosts the realtime service. An attacker only needs to send HTTP POST requests to the internal endpoints; no authentication headers are required, but the endpoints are intended to be protected by traditional access controls. The lack of authentication is the primary weakness, allowing remote or local compromise of the internal messaging streams.
OpenCVE Enrichment