Impact
The vulnerability enables a low‑privileged attacker who has access to the physical communication segment attached to the hardware running Oracle Agile Engineering Data Management to create, delete, modify, or otherwise gain unauthorized access to all critical data stored in the system. The impact includes full confidentiality and integrity compromise of available data, with no availability impact reported.
Affected Systems
Oracle Agile Engineering Data Management version 6.2.1 is the only affected product. The vulnerability is tied to the Engineering Communication Interface component of this product, and the attack requires physical proximity or access to the communication network segment.
Risk and Exploitability
The CVSS 3.1 base score of 7.3 indicates a high severity, and the vector of AV:A/AC:L/PR:L/UI:N/S:U shows the attack is local, requires low effort, and does not need user interaction. The EPSS score of less than 1% suggests exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, should the flaw be leveraged, the consequences would be severe, particularly given the breadth of data that could be accessed or altered.
OpenCVE Enrichment