Impact
A missing authorization check in Armiya Information Technologies Ltd. Co. Access Control System (GKS) lets attackers collect data from common resource locations without proper credentials, effectively bypassing the system’s access controls (CWE-862). The flaw permits unauthorized read access to protected information, potentially exposing sensitive data and enabling further malicious activity within the environment.
Affected Systems
Armiya Information Technologies Ltd. Co. Access Control System (GKS) is vulnerable in all releases prior to version 2; no other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 8.2 indicates a high‑severity vulnerability. An EPSS score of less than 1% points to a very low exploitation probability, and the issue is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers could send requests directly to the GKS API or administrative interface to exploit the missing authorization checks. Anyone with network access to the GKS services could execute this attack, underscoring the need for protective measures.
OpenCVE Enrichment