Impact
The vulnerability in GAPTEQ Designer v3.5 allows a remote attacker to elevate privileges by leveraging the Company Manager role. This flaw gives users non‑privileged access an administrative level, enabling them to perform actions that should be restricted. By gaining such privileges, an attacker could compromise confidentiality, integrity, and availability of the application and potentially the underlying systems. The weakness is a classic case of improper authorization (CWE‑269).
Affected Systems
Products affected are GAPTEQ Designer version 3.5. No specific sub‑version or patch level information is provided, so all releases of v3.5 are potentially impacted.
Risk and Exploitability
Based on the provided information, the vulnerability in GAPTEQ Designer v3.5 carries a CVSS score of 9.8, indicating critical severity. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can remotely exploit the flaw to elevate privileges to the Company Manager role, potentially gaining full administrative control and compromising the confidentiality, integrity, and availability of the system. Since the description does not specify authentication prerequisites, it is possible that the exploit could be carried out by unauthenticated network users; however, the exact attack vector remains unspecified in the CVE details.
OpenCVE Enrichment