Impact
The vulnerability is a path traversal flaw present in SKYSEA Client View and SKYMEC IT Manager. An attacker who logs into a Windows system running the affected product can use the flaw to traverse directories and cause the application to read or write unauthorized files. Because the affected products also process UDP packets, an attacker may execute arbitrary code on another Windows system that simultaneously has the products installed and can receive UDP traffic from the compromised host. The weakness corresponds to CWE‑25, reflecting improper access to array elements or pointers.
Affected Systems
Affected vendors include Sky Co., LTD., with products SKYSEA Client View and SKYMEC IT Manager. No specific version information was supplied. Users of any installation of these products on Windows should consider the possibility of the flaw until a patch is released.
Risk and Exploitability
The CVSS score of 5.8 indicates a medium severity rating. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires legitimate login on a Windows host, but as soon as the attacker can trigger the path traversal, code can be executed on a remote satellite system that accepts UDP messages. The official advisory notes that the issue originates from an incomplete fix of CVE‑2024‑41726, possibly indicating a recurring flaw. Attackers would likely exploit it by sending crafted UDP packets after logging in, so the vector is likely remote but requires authentication on the local machine.
OpenCVE Enrichment