Impact
The vulnerability in Brainzcompany Zenius EMS 8.0 arises from an authentication bypass that can be achieved via an alternate path or channel, combined with improper validation of syntactic correctness of input. This flaw enables an attacker to inject code that the server will execute, resulting in remote code inclusion. The primary impact is remote code execution, allowing an attacker to compromise confidentiality, integrity, and availability of the affected system. The weakness is classified under CWE‑1286 Authentication Bypass and CWE‑288 Improper Validation.
Affected Systems
Brainzcompany Zenius EMS 8.0, Build OAM 109 is the only affected version identified. No additional affected products or versions are listed.
Risk and Exploitability
With a CVSS score of 8.7 the vulnerability is considered high severity. The EPSS score is not available, but the lack of an existing KEV listing does not diminish the risk posed by the flaw. The likely attack vector is remote, through the application’s web interface or other exposed channels that permit the use of the alternate authentication path. The vulnerability requires remote access to the application but does not demand local privileges or pre‑existing authentication, making it potentially exploitable by unauthenticated or low‑privilege attackers.
OpenCVE Enrichment