Impact
A flaw in Oracle Agile PLM MCAD Connector version 3.6 allows an attacker who can access the hardware’s physical communication segment to gain low‑privilege access to the connector. The vulnerability enables the attacker to read, insert, update or delete data exposed by the connector, thereby compromising the confidentiality and integrity of the system’s data while not affecting availability. The weakness originates from insufficient authorization controls within the CAX Client component, as the attacker can perform privileged operations without proper checks.
Affected Systems
The affected product is Oracle Agile PLM MCAD Connector from Oracle Corporation, specifically version 3.6.
Risk and Exploitability
The calculated CVSS score is 4.6, indicating moderate severity with low confidentiality and integrity impacts. Exploitation requires physical access to the communication interface, and the attacker must already have low‑level privileges on the connected hardware. The EPSS score is less than 1 percent and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower exploitation probability at the time of analysis. However, because the attack vector is local and physical, the risk remains significant for environments where such access is possible or inadequately protected.
OpenCVE Enrichment