Impact
The CVE allows an attacker with local network access to bypass the application's rate‑limiting mechanism, thus permitting brute‑force attempts against the screen‑sharing code and potentially triggering the display of malicious content. This flaw falls under CWE‑307, reflecting an authentication management weakness that undermines protective controls.
Affected Systems
Affected systems include ESharePro, part of the EShare suite. No specific version numbers are disclosed, so all deployed instances of ESharePro may be vulnerable unless updated.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity, and the EPSS score of less than 1% confirms a very low likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires local network access, so the attack vector is internal; combined with the low score, the overall risk remains low.
OpenCVE Enrichment