Impact
The vulnerability is an incorrect authorization that permits an authenticated low‑privileged user to elevate privileges to root on the appliance. This can lead to full system compromise, allowing an attacker to read, modify, or delete any data, install malware, or disrupt services. The weakness is identified as CWE‑863.
Affected Systems
Progress Software ECS Connection Manager, LoadMaster, Object Scale Connection Manager, and MOVEit WAF. Versions are not listed in the advisory; affected appliances should check the vendor for applicable patches.
Risk and Exploitability
The advisory assigns a CVSS score of 8, indicating high severity. The EPSS score is 0.00169, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, reducing confidence in widespread public exploitation but does not eliminate risk. The likely attack vector requires an attacker to be authenticated with a low‑privileged account; from there, the improper authorization can be leveraged through the appliance’s management interface to gain root access. No public exploit code is reported, but the high severity and privileged escalation potential make this a critical concern.
OpenCVE Enrichment