Impact
The vulnerability exists in the CAX Client component of Oracle’s Agile PLM MCAD Connector. An unauthenticated attacker who has physical access to the device’s communication segment can exploit the flaw, enabling them to insert, update, or delete data and to read protected data. The primary impact is that confidentiality and integrity of the protected data can be compromised because sensitive configuration or business information may be altered or exposed.
Affected Systems
Oracle Corporation’s Agile PLM MCAD Connector version 3.6 is the only affected release listed. No other versions or components are known to be vulnerable at this time.
Risk and Exploitability
The CVSS base score of 3.7 indicates low overall impact, and the EPSS score of less than 1 percent reflects a very low likelihood of exploitation. The attack requires physical proximity and human interaction, so restricting access to the hardware significantly mitigates risk, but the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment