Impact
The Oracle Utilities Network Management System suffers from an access‑control weakness and an authentication bypass. An attacker who can reach the system’s HTTP interface without prior authentication can read all data exposed by the platform and modify or delete data that is otherwise protected. The flaw therefore threatens both the confidentiality and integrity of utilities information, enabling compromised visibility into network planning or ability to alter critical operational records.
Affected Systems
The product is Oracle Utilities Network Management System from Oracle Corporation. Affected releases include 2.5.0.2.0 through 2.5.0.2.13, 2.6.0.1.0 through 2.6.0.12B, 2.6.0.2.0 through 2.6.0.2.10A, and 25.12.0.0.0 through 25.12.0.0.3. All listed versions remain vulnerable until the vendor issues a fix.
Risk and Exploitability
The CVSS base score of 8.2 classifies the flaw as high severity, while the EPSS score of less than 1% indicates a low current probability of exploitation. The vulnerability is not listed in CISA KEV, confirming it is not a known exploited vulnerability cataloged by the agency. The likely attack vector is a remote unauthenticated HTTP request; no credentials are required and the exploit can be performed by anyone with network connectivity to the exposed endpoint.
OpenCVE Enrichment