Impact
The vulnerability (CWE‑201) allows sensitive information to be inserted into outgoing data, enabling an attacker to bypass authentication and gain unauthorized access to protected resources. This results in a potential compromise of confidentiality and integrity of the system’s data.
Affected Systems
Sayax Energy Technologies Inc. OSOS, affected through version 09072026.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, and the vendor has not yet released a fix. Based on the description, it is inferred that the attack vector is remote via network traffic that carries the inserted sensitive data. Overall, the risk is moderate due to the moderate severity, but the low exploitation likelihood reduces the immediate threat level.
OpenCVE Enrichment