Impact
An improper access control check in CatchPulse’s named pipe communication interface allows an attacker to invoke CatchPulse functions that are normally protected by stricter security policies. The flaw effectively bypasses the intended privilege enforcement, enabling authorized actions to be executed by users or processes that should not have such permissions. The impact is a loss of confidentiality and integrity of the data processed by the restricted functions, as well as potential escalation of privileges for the attacker.
Affected Systems
The vulnerability affects SecureAge’s CatchPulse product. No specific version information is provided in the advisory, so any installation that includes the named pipe communication interface may be susceptible. The flaw resides in the inter‑process communication layer used by CatchPulse to receive commands from external clients.
Risk and Exploitability
The CVSS score of 5.2 classifies the vulnerability as moderate in severity. Attackers would need to target the named pipe, which typically involves local or same‑host access; the exact attack vector is not explicitly stated in the advisory, so it is inferred to be local. Because the EPSS score is not available, the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the ability to invoke protected functions without proper authorization justifies a prompt patch.
OpenCVE Enrichment