← volver
CVE-2025-34143criticalexplotación observadaCWE-269CWE-288CWE-78

ETQ Reliance CG Authentication Bypass via Trailing Space RCE

77Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actcvss 9.3epss 31%
de la publicación al arma
Publicada en NVD22 jul
VulnCheck+11d
probabilidad de explotación
31%top 2% de las CVE
explotación observada
VulnCheck
An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login as the privileged internal SYSTEM user by manipulating the username field. The SYSTEM account does not require a password, enabling attackers with network access to the login page to obtain elevated access. Once authenticated, an attacker could achieve remote code execution by modifying Jython scripts within the application. This issue was resolved by introducing stricter validation logic to exclude internal accounts from public authentication workflows in version MP-4583.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
ETQ · Reliance CG (legacy)