ZeroHour

CVE-2016-7836

KEV PoC large

Unauthenticated RCE in SKYSEA Client View Management Console

CISA: SKYSEA Client View Improper Authentication Vulnerability

CVSS 3.1
9.8 critical
EPSS
19%p97
Published
()
KEV added
AI analysis

SKYSEA Client View Ver.11.221.03 and earlier contains an improper authentication flaw (CWE-287) in the processing of authentication on the TCP connection used with the management console program. An attacker with network reachability to that TCP service can send crafted authentication data that triggers remote code execution with no credentials, no user interaction, and no special conditions (CVSS 3.1: 9.8). Successful exploitation gives the attacker full code execution on the console side, with high impact to confidentiality, integrity, and availability, and potential access to the managed-client inventory the console controls. Organizations running SKYSEA Client View Ver.11.221.03 or earlier are affected; the product is a client/IT-asset management suite deployed largely by Japanese organizations. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on October 14, 2025, indicating confirmed in-the-wild exploitation, and EPSS currently estimates a 19.4% probability of exploitation within 30 days.

What to do: Upgrade SKYSEA Client View to a fixed release later than Ver.11.221.03 as directed in Sky Group's security advisory (https://www.skygroup.jp/security-info/170308.html), and inventory any console running Ver.11.221.03 or older. Until patched, restrict access to the management console TCP port from untrusted network segments and review console servers for signs of compromise. CISA KEV requires applying vendor mitigations or discontinuing use within the BOD 22-01 timeline.

Affected
Sky Group (skygroup) SKYSEA Client ViewVer.11.221.03 and earlier
Estimated exposure
largeon the order of tens of thousands of management console deployments (product has a cumulative licensed base of millions of endpoints, concentrated in Japan) — SKYSEA Client View is a long-standing top-share IT asset management product in Japan with millions of cumulative licensed endpoints, and the vulnerable management console service is typically deployed once per customer organization on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

CISA Known Exploited Vulnerability
Affected
SKYSEA Client View
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
skygroup
Products
skysea client view
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news