Impact
The vulnerability is a missing authorization flaw that allows callers to access functionality not properly constrained by access control lists. The platform exposes chat‑bot tool endpoints through its API, so an attacker who can reach those endpoints can trigger operations that should otherwise be restricted. This enables the creation of unauthorized chatbot instances or execution of user‑supplied actions, though the advisory does not indicate direct data exfiltration or back‑door access. Based on the description, the likely attack vector involves remote API exposure to bypass ACLs.
Affected Systems
HAVELSAN Inc. Sef - AI Chatbot Platform, versions prior to 2.1. The platform is specifically affected only before the 2.1 release, with no other versions mentioned in the advisory.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity, indicating the flaw may lead to unauthorized actions but not catastrophic compromise. The EPSS score of 0.21% (0.0021) indicates a very low but non-zero exploitation probability, and the vulnerability is not listed in CISA KEV. Attackers are likely to use authenticated access or exploit any exposed endpoints to bypass ACLs, which suggests the vulnerability could be leveraged by threat actors with network access to the platform. Given the moderate CVSS and the low EPSS value, the overall risk is present but limited to users with the ability to reach the platform’s interfaces.
OpenCVE Enrichment