Impact
The vulnerability allows session tokens that skip the scope validation performed by the RequireScopes middleware to access admin‐only endpoints. An attacker who already has a valid authenticated session can read system logs, visitor statistics, user email addresses and subscribe to live WebSocket logs, exposing sensitive internal information and potentially aiding further compromise.
Affected Systems
Vendor lin‑snow offers Ech0. All releases before version 4.5.1 are affected. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers need a valid session token, so the attack vector is an authenticated web session or a stolen session cookie. Once privileged endpoints are accessed, attackers can gather confidential data and potentially establish persistence through WebSocket logs.
OpenCVE Enrichment