Impact
The PayRange API fails to enforce authorization on its management endpoints, which means that anyone can send requests to these endpoints without needing an account and receive detailed information about every device on the PayRange network. This flaw leads to a direct information disclosure, allowing potential attackers to map network assets and gather sensitive operational data that could be leveraged for further attacks. The weakness corresponds to an improper authorization failure.
Affected Systems
The vulnerability affects the PayRange API product, as identified by the CNA. No specific product versions were listed in the available data, so all current deployments of the PayRange API are potentially impacted until a fix is applied by the vendor.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as high severity, and the EPSS score is currently unavailable, indicating that the exploitation probability is not quantified but could still be significant. The vulnerability is not included in CISA’s KEV catalog, suggesting it may not yet have known exploits in the wild. Attackers can abuse the publicly accessible endpoints over the network, likely via standard HTTP requests to the API, without needing credentials. Inferred from the description, the attack vector is external over the network, requiring no special privileges or insider access.
OpenCVE Enrichment