Impact
This vulnerability is difficult to exploit and allows an unauthenticated attacker who has access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise the connector. A successful exploitation can result in unauthorized access to critical data or complete access to all data the connector can reach. The flaw represents an access control weakness (CWE‑284). The CVSS 3.1 score of 5.3 indicates a medium‑to‑high impact with a focus on confidentiality.
Affected Systems
Affected system is Oracle Agile PLM MCAD Connector from Oracle Corporation, version 3.6. The product requires a hardware module with a dedicated physical communication segment.
Risk and Exploitability
With a CVSS 3.1 base score of 5.3 and vectors AV:A, AC:H, PR:N, UI:N, S:U, C:H, the vulnerability poses a moderate risk when the connector is physically accessible. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation, and the flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. Nonetheless, the requirement for physical or adjacent network access means that environments lacking strict physical security or network segmentation could be vulnerable to exploitation.
OpenCVE Enrichment