CVE-2016-7836
KEV PoC largeUnauthenticated RCE in SKYSEA Client View Management Console
CISA: SKYSEA Client View Improper Authentication Vulnerability
SKYSEA Client View Ver.11.221.03 and earlier contains an improper authentication flaw (CWE-287) in the processing of authentication on the TCP connection used with the management console program. An attacker with network reachability to that TCP service can send crafted authentication data that triggers remote code execution with no credentials, no user interaction, and no special conditions (CVSS 3.1: 9.8). Successful exploitation gives the attacker full code execution on the console side, with high impact to confidentiality, integrity, and availability, and potential access to the managed-client inventory the console controls. Organizations running SKYSEA Client View Ver.11.221.03 or earlier are affected; the product is a client/IT-asset management suite deployed largely by Japanese organizations. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on October 14, 2025, indicating confirmed in-the-wild exploitation, and EPSS currently estimates a 19.4% probability of exploitation within 30 days.
What to do: Upgrade SKYSEA Client View to a fixed release later than Ver.11.221.03 as directed in Sky Group's security advisory (https://www.skygroup.jp/security-info/170308.html), and inventory any console running Ver.11.221.03 or older. Until patched, restrict access to the management console TCP port from untrusted network segments and review console servers for signs of compromise. CISA KEV requires applying vendor mitigations or discontinuing use within the BOD 22-01 timeline.
| Sky Group (skygroup) SKYSEA Client View | Ver.11.221.03 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.
- Affected
- SKYSEA Client View
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- skygroup
- Products
- skysea client view
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H