Impact
Salto ProAccess Space uses a tenancy or logical partitioning feature that, when misconfigured or improperly implemented, can allow an authenticated user to bypass intended access controls and access spaces managed by the product. The vulnerability, identified as CWE‑639, can lead to unauthorized reading or modification of assets in partitions other than the one assigned to the attacker.
Affected Systems
All installations of SALTO ProAccess Space that employ the tenancy or logical partitioning functionality, especially those running versions prior to 6.13. Users who have not upgraded to 6.13 must consider their deployment exposed to this authorization bypass.
Risk and Exploitability
The flaw has a CVSS score of 7.1, indicating a high severity impact. The EPSS score is less than 1%, suggesting a very low probability of known exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. While the description does not specify an explicit attack vector, it is inferred that an authorized attacker could exploit the flaw by exploiting a flaw in the partitioning logic to gain access to other spaces. Vulnerability mitigation requires upgrading to version 6.13, and post‑patch hardening measures are recommended.
OpenCVE Enrichment