Impact
The vulnerability in Oracle Enterprise Command Center Framework v16 is an improper authentication flaw that allows an unauthenticated actor who can connect to the physical communication segment of the hardware to assume full control of the framework. The weakness, classified as CWE-306, results in loss of confidentiality, integrity, and availability of the framework and any systems managed by it, effectively allowing a total takeover.
Affected Systems
Oracle Enterprise Command Center Framework version 16, part of Oracle E‑Business Suite, is the only product and version affected as listed by Oracle. No other versions are indicated in the advisory.
Risk and Exploitability
The CVSS base score of 8.8 signals a high severity risk, while the EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Because exploitation requires direct physical connection to the hardware’s communication segment, the attack vector is limited to insiders or adversaries able to be physically present in the environment. Nevertheless, a successful attack would result in total compromise of the framework, making the risk high.
OpenCVE Enrichment