Impact
Improper access control on the Synergis Softwire installation folder allows an attacker to read, modify, or delete critical configuration files. This lack of permission checks can enable privilege escalation, arbitrary code execution, or disruption of the Streamvault all‑in‑one appliance’s operation. The flaw is classified as CWE‑922, indicating unchecked file access vulnerability.
Affected Systems
The vulnerability affects Genetec Inc.’s Synergis Softwire installations, including the Streamvault all‑in‑one appliances such as the SV‑100E and SV‑300E series and deployments on Windows servers. Fixed versions are identified by Genetec in their 12.0.2 and 12.2.0 advisories, but explicit affected versions for the flaw are not listed in the public data.
Risk and Exploitability
With a CVSS score of 7.9 the flaw is considered high severity, offering significant impact if exploited. The EPSS score is unavailable, so the likelihood of exploitation is unknown, though the lack of directory restrictions makes the attack path straightforward for anyone who can locate or reach the installation folder. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed active exploitation as of now.
OpenCVE Enrichment