Impact
An issue in GAPTEQ Designer v3.5 allows a remote attacker to elevate privileges through the Company Manager role. The flaw enables non‑privileged users to gain administrative permissions within the application, compromising confidentiality, integrity, and availability of the system. This is a classic example of improper authorization where the application does not correctly validate user roles before granting access to privileged functions.
Affected Systems
Products affected are GAPTEQ Designer version 3.5. No specific sub‑version or patch level information is provided, so all releases of v3.5 are potentially impacted.
Risk and Exploitability
The vulnerability can be exploited over the network by an attacker who can access the application. There is no EPSS score available and the issue is not listed in the CISA KEV catalog, so the exact likelihood of exploitation is unknown, but the potential to elevate privileges to a Company Manager role carries a high risk. Attackers would need to authenticate with a compromised or low‑privileged account and then trigger the privilege escalation path described in the product’s design.
OpenCVE Enrichment