Impact
Vimesoft Inc. Enterprise Video Platform suffers from a missing authorization vulnerability (CWE-862) that permits attackers to invoke restricted functionalities which should be protected by access control lists. This flaw allows unauthorized exploitation of platform features that are not properly constrained by ACLs, creating a window for abuse of protected operations.
Affected Systems
The vulnerability impacts Vimesoft Inc. Enterprise Video Platform versions 3.11.0.0 through, but not including, 3.25.0. Administrators should verify that installed instances fall within this range.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity, and the EPSS score of less than 1% suggests a low but non-zero likelihood of exploitation at present. The issue is not listed in the CISA KEV catalog. While the CVE description does not specify an attack vector, it is inferred that remote exploitation is possible through the platform’s network interfaces, provided the attacker can reach the service.
OpenCVE Enrichment