Digiwin EasyFlow .NET and EasyFlow AiNet Missing Authentication Vulnerability Allowing Database Administrator Credential Access

Vulnerability

A missing authentication vulnerability has been identified in Digiwin's EasyFlow .NET (versions through 6.6.19) and EasyFlow AiNet (versions through 8.1.1). This vulnerability allows unauthenticated remote attackers to obtain database administrator credentials by exploiting a specific functionality within the applications.

Impact

Exploitation of this vulnerability allows for unauthorized access to database administrator credentials, potentially leading to further unauthorized actions within the database or application.

Remediation

Users are advised to update EasyFlow .NET to version 6.6.19 and install patch 20250520. For EasyFlow AiNet, update to version 8.1.1 and also install patch 20250520.

Added: Oct 21, 2025, 7:17 AM
Updated: Oct 21, 2025, 7:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
5.0
exploitability
7.0
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.