Impact
AlanWeb SCADA fails to enforce authorization for certain directories, enabling an unauthenticated user to read any file in those directories and to execute a subset of them. The vulnerability is particularly dangerous because it permits direct execution of PHP scripts that interact with the connected database, giving the attacker the ability to read, modify, or delete data and potentially achieve full remote code execution. This flaw corresponds to a missing authorization weakness (CWE‑862).
Affected Systems
The vulnerable product is AlanWeb SCADA. All releases before version 9.8.5 are susceptible; version 9.8.5 and later include the fix and are no longer affected.
Risk and Exploitability
The CVSS score of 8.8 signals a high‑severity issue. An EPSS score of <1% (0.00294) indicates a very low probability of exploitation and the vulnerability is not listed in the CISA KEV catalogue, but based on the description the likely attack vector is via unauthenticated HTTP requests to the affected directories. It is inferred that an external network user could simply request these directories to read or execute files, potentially gaining full control over the system. The combination of high severity and ease of exploitation results in a high overall risk that should be addressed swiftly.
OpenCVE Enrichment