Impact
An unauthenticated attacker can reach the Progress ShareFile Storage Zones Controller and view restricted configuration pages. This access allows the attacker to modify system settings that may enable arbitrary code execution, thereby compromising the confidentiality, integrity, and availability of the affected environment. The weakness is an access control failure (CWE-284) compounded by insecure design (CWE-698).
Affected Systems
The vulnerability affects all deployed instances of the Progress ShareFile Storage Zones Controller. No specific version range is listed, so any integrated SZC service could potentially be impacted.
Risk and Exploitability
The CVSS score of 9.8 signals a critical level of risk. Based on the description, it is inferred that the attack vector is remote and requires no authentication, meaning any external host can launch the exploit. The EPSS score of approximately 0.58% indicates a very low probability of exploitation in the current threat landscape. Although the vulnerability is not listed in CISA's KEV catalog, the combination of remote, unauthenticated access and the potential for arbitrary code execution makes the threat substantial.
OpenCVE Enrichment