AI analysis
Ahsay AhsayCBS through version 10.3.2 has an improper authentication flaw (CWE-287) in the checkSysPwd function of com/ahsay/obs/api/ApiStructsAction.java in the API component. A remote attacker can trigger it by manipulating the random argument, with no prior privileges and no user interaction. The published impact is low confidentiality, integrity, and availability loss (CVSS 4.0 base 5.5), not a described remote code execution. Organizations running affected AhsayCBS backup servers are affected, and upgrading to 10.3.4 mitigates the issue. The advisory states that an exploit is public and may be used (CVSS exploit maturity Proof-of-Concept); this CVE is not in CISA KEV, and a related headline about threat actors using critical AhsayCBS flaws to plant webshells and XMRig is not confirmed to be this medium-severity bug.
What to do: Upgrade AhsayCBS to version 10.3.4. Until that is done, limit network access to the AhsayCBS API to trusted management hosts and review API and authentication logs for unexpected checkSysPwd activity.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component.