Impact
The vulnerability in Seres Software syWEB allows an attacker to observe discrepancies that reveal whether specific user accounts exist, effectively enabling account footprinting. This weakness falls under CWE-203, which addresses user enumeration or information disclosure that permits an adversary to determine valid credentials or active usernames without authentication. Such enumeration can be leveraged in credential stuffing, phishing, or targeted attacks once an attacker knows legitimate account names.
Affected Systems
Seres Software’s syWEB product versions up to and including 27082026 are affected. The product is no longer supported by the vendor, meaning no future security updates or patches will be released for these versions.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate level of severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The vendor’s statement that the product is unsupported increases the risk of exploitation because no fix exists to mitigate the flaw. The likely attack vector is through the web interface of syWEB, where query responses can leak account existence information, but this is inferred from the description of account footprinting rather than explicitly stated.
OpenCVE Enrichment