Impact
The vulnerability in PALLET CONTROL products arises from an incorrect default permission setting that permits a local attacker to execute arbitrary code with SYSTEM privileges. This flaw allows an attacker who has local access to the affected machine to gain full control over the system, potentially compromising all data and operations handled by the application.
Affected Systems
Vendors of concern are JAL Information Technology Co., Ltd. The impacted products include PALLET CONTROL, PalletControl, and PalletControl Cloud. No specific version information is provided, so every install of these products may be susceptible.
Risk and Exploitability
The CVSS base score of 8.5 indicates a high severity vulnerability. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The primary attack vector is local; an attacker must already have physical or local network access to the device running the software to exploit this issue. Once exploited, the attacker obtains SYSTEM level rights, enabling complete takeover of the affected system.
OpenCVE Enrichment