Impact
The flaw is an incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server version 2.7.6. Authenticated users with low-level privileges can invoke the API to remove the server’s license, resulting in a denial‑of‑service condition as legitimate users lose access to the licensed services. The weakness is classified as CWE‑284, improper access control, due to lacking enforcement of appropriate privilege checks before executing the license removal operation.
Affected Systems
Affected systems are CAXPerts UniversalPlantViewer WebServices Server v2.7.6. No other versions or product variants are documented. The vulnerability is specific to the deactivateOffline API endpoint, which removes the license file from the server.
Risk and Exploitability
The vulnerability has a CVSS base score of 6.5, indicating moderate severity. The EPSS score is below 1 %, reflecting a low likelihood of exploitation at present. It is not listed in the CISA KEV catalog. Exploitation requires an authenticated session; an attacker who can obtain credentials for a user with permissive rights can call the deactivateOffline endpoint and trigger a DoS. The impact is a disruption of licensed services, resulting in downtime for legitimate users.
OpenCVE Enrichment