Impact
Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to be interpreted as executable code by an agent running in a privileged automation environment. The vulnerability essentially lets an external attacker submit fabricated Sentry events without any authentication, source repository access, or infrastructure credentials, resulting in the agent executing data that has been crafted to run in its context. This flaw exposes confidentiality, integrity, and availability of the automation system and any resources it controls.
Affected Systems
Functional Software, Inc. Sentry Seer. No specific version information is provided in the available data, so all installations of the product remain a potential target until a patch is applied or the vulnerability is mitigated.
Risk and Exploitability
The flaw carries a high potential impact, as reflected by its CVSS score of 9.8, due to the remote nature of the attack and the privilege level at which the agent operates. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating that the current likelihood of exploitation in the wild is low. Nevertheless, any exposed ingestion point could be used by an attacker to introduce malicious telemetry. The likely attack vector is remote network access to the telemetry ingestion API, and the attacker does not need authentication to exploit the weakness.
OpenCVE Enrichment