Impact
The vulnerability is an improper certificate validation flaw in Pgpool-II that allows an unauthenticated attacker to bypass client certificate authentication, which can lead to unauthorized access to the backend database services. The weakness is identified as CWE-295. Attackers would be able to connect to Pgpool-II using arbitrary certificates or without any authentication, depending on server configuration. The impact is a loss of authentication integrity, potentially enabling data theft or manipulation.
Affected Systems
Affected systems are those running Pgpool-II from the Pgpool Global Development Group. No specific version numbers are disclosed, so all deployments of Pgpool-II should be examined for the presence of this issue. The product must be checked for manufacturer guidance on mitigation.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate risk, and the EPSS score is not available, suggesting limited publicly known exploit data. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely remote network access; an attacker can reach the Pgpool-II service over the network and perform the bypass without needing any existing credentials. Organizations should assume the flaw could be used to gain full database access where Pgpool-II is configured to forward requests.
OpenCVE Enrichment