Digiwin EasyFlow .NET
cpe:2.3:a:digiwin:easyflow_.net:*:*:*:*:*:*:*
- <= 6.6.19
A missing authentication vulnerability has been identified in Digiwin's EasyFlow .NET (versions through 6.6.19) and EasyFlow AiNet (versions through 8.1.1). This vulnerability allows unauthenticated remote attackers to obtain database administrator credentials by exploiting a specific functionality within the applications.
Exploitation of this vulnerability allows for unauthorized access to database administrator credentials, potentially leading to further unauthorized actions within the database or application.
Users are advised to update EasyFlow .NET to version 6.6.19 and install patch 20250520. For EasyFlow AiNet, update to version 8.1.1 and also install patch 20250520.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.