Impact
The vulnerability resides in the DefaultFunction of 3CORESec Trapdoor up to version 1.2.2. It causes a weakness in access control that allows attackers to gain unauthorized operation of the function. This flaw can be triggered remotely, giving an attacker the ability to perform actions normally restricted to privileged users. The impact is a potential compromise of confidentiality, integrity, or availability of the system depending on the function’s role within the application.
Affected Systems
Affected systems include 3CORESec Trapdoor versions up to and including 1.2.2. Users running any installation of this software that has not applied the vendor’s fix or updated to a newer patch level may be vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. No EPSS score is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Because the attack can be initiated remotely and the breadth of affected versions is limited, the likelihood of exploitation is moderate, but systems should prioritize remediation to avoid potentially disruptive unauthorized access.
OpenCVE Enrichment