Impact
The vulnerability is a missing authentication for a critical function, classified as CWE‑306. It allows an attacker who can reach the affected component to execute that function without providing credentials, potentially enabling full control over critical industrial processes or data. The impact is the loss of confidentiality, integrity, and availability of the system’s managed assets because the bypass removes the guard that normally protects sensitive operations.
Affected Systems
This issue affects Talassoft Industrial Management Software produced by TMT Machine Industry and Trade Ltd. Co. Versions from V4 up to, but not including, V16 are vulnerable. No other versions are explicitly listed as affected.
Risk and Exploitability
The CVSS v3.1 score of 7.5 indicates a high severity, while the EPSS score is not publicly available. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation at the time of analysis. The likely attack vector is remote, as the function can be accessed over the network. An attacker with network access to the software can call the vulnerable endpoint and bypass authentication, potentially achieving privilege escalation or full control of the industrial environment.
OpenCVE Enrichment