Impact
The vulnerability allows an unauthenticated attacker who has physical access to the communication segment connected to the hardware to compromise the Oracle Agile PLM MCAD Connector. By exploiting this weakness, the attacker can read critical data and perform unauthorized insert, update, or delete operations. According to the CVSS vector, the attack compromises confidentiality heavily (C:H) and integrity moderately (I:L).
Affected Systems
Oracle Agile PLM MCAD Connector version 3.6 is the only affected product listed in the advisory. This component is part of Oracle Supply Chain’s MCAD Connector and no other versions are indicated as impacted.
Risk and Exploitability
The CVSS Base Score of 5.9 indicates moderate severity. The attack requires local access (AV:A) with high complexity (AC:H) and no privileges (PR:N). The EPSS score of approximately 0.18% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and the lack of a known remote exploitation vector further reduces the likelihood of widespread attacks. Nonetheless, the high confidentiality impact means that once the physical channel is compromised, sensitive data can be exfiltrated or altered.
OpenCVE Enrichment