Impact
The vulnerability is an unverified password change flaw that allows an attacker to modify a user’s password without proper authentication. Because authentication is bypassed, an attacker can gain full control of the affected account, compromising confidentiality and integrity of the platform data.
Affected Systems
Vimesoft Inc.’s Enterprise Video Platform versions 3.11.0.0 through 3.25.0 (inclusive of 3.11.0.0 and exclusive of 3.25.0) are vulnerable.
Risk and Exploitability
The CVSS score of 9.8 ranks the flaw as critical, while the EPSS score of less than 1% indicates that widespread exploitation has not yet been observed. The vulnerability is not listed in CISA KEV. Likely attack vectors are remote, via the web interface that handles password changes. Anyone with access to the password change endpoint could exploit this weakness. Given the high severity, vendors’ patches or upgrades should be applied as a priority.
OpenCVE Enrichment