Impact
Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy allows an attacker who has physical access to the communication segment connected to the hardware to bypass authentication and gain unauthorized access to the proxy. Successful exploitation can lead to reading critical data with high confidentiality impact and modifying or deleting data, producing integrity impact. The vulnerability appears to involve an access control issue, inferred from the fact that users without credentials can interact with protected resources.
Affected Systems
Oracle Communications Cloud Native Core Security Edge Protection Proxy versions 26.1.200 and 25.2.201.
Risk and Exploitability
The CVSS 3.1 Base Score of 7.1 indicates a high severity risk. The EPSS score of less than 1% reflects a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Because the attack vector requires physical access to the communication segment attached to the hardware where the SEPP runs, the attacker does not need remote network interaction; physical connectivity alone is sufficient to exploit an access control weakness, inferred from the description indicating unauthenticated interaction.
OpenCVE Enrichment