Impact
The vulnerability resides in the XCB daemon of the PAX Technology Q80. Authentication is omitted before granting access to daemon functions, allowing an attacker to read confidential information and alter configuration settings. The flaw is a straightforward authentication failure, categorized as CWE‑306. Combined with other weaknesses, an adversary could execute arbitrary code in the context of the operating system’s root user.
Affected Systems
Affected systems are installations of the PAX Technology Q80 platform, specifically the XCB daemon component. No specific version data is available, so any deployment of the Q80 may be impacted.
Risk and Exploitability
The CVSS score is 7.1, indicating a moderate to high impact. EPSS data is not available, so the probability of exploitation is unclear, but the lack of authentication and the potential for root execution raise concern. The vulnerability is not listed in the CISA KEV catalog. Exploitation likely requires network adjacency or accessible network interfaces to the XCB service, as authentication is not required to interact with the daemon.
OpenCVE Enrichment