CVE-2025-34143
moderateAuthentication Bypass Leading to RCE in ETQ Reliance Legacy CG Platform
ETQ Reliance on the legacy CG (compliance generation) platform fails to validate the username field during login, allowing an unauthenticated attacker to authenticate as the privileged internal SYSTEM account, which requires no password. An attacker with network access to the login page simply submits the internal account name to bypass authentication entirely and gain elevated access to the application. Once authenticated, the attacker can achieve remote code execution on the server by modifying the Jython scripts that the application executes. All deployments of the legacy CG platform prior to patch MP-4583 are affected, and no special privileges or user interaction are required. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the elevated EPSS score (~32% probability of exploitation within 30 days, 98th percentile) suggests defenders should prioritize remediation.
What to do: Upgrade ETQ Reliance legacy CG deployments to patch MP-4583 or later, which excludes internal accounts like SYSTEM from public authentication workflows. Until patched, restrict network access to the login page via firewall rules or VPN, and review authentication logs for logins to the SYSTEM account and unexpected changes to Jython scripts. After patching, verify no unauthorized scripts or accounts were left behind on previously exposed instances.
| ETQ Reliance (legacy CG platform) | legacy CG platform releases prior to patch MP-4583 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login as the privileged internal SYSTEM user by manipulating the username field. The SYSTEM account does not require a password, enabling attackers with network access to the login page to obtain elevated access. Once authenticated, an attacker could achieve remote code execution by modifying Jython scripts within the application. This issue was resolved by introducing stricter validation logic to exclude internal accounts from public authentication workflows in version MP-4583.
- Weakness
- CWE-78, CWE-269, CWE-288
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X