Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the system as any user.
The vulnerability, classified as CWE-1390 (Weak Authentication), results from improper implementation of the authentication mechanism in Borg SPM 2007. A remote attacker, without any prior authentication, can bypass the identity verification procedure and gain access to the system with privileges of any chosen user account. No user interaction or special environmental conditions are required to conduct the attack.
An attacker can take full control of user accounts in the system, including accounts with elevated privileges, leading to violations of confidentiality, integrity, and availability of data processed by the application.
The product is discontinued and likely no longer supported by the vendor. Apply patches available from the vendor according to references (TWCERT). It is strongly recommended to immediately discontinue the product and replace it with a currently supported solution. Until migration is complete, isolate the system from public networks using firewalls or other network access control mechanisms.
Borg SPM 2007 produced by BorG Technology Corporation (product discontinued from sales in 2008)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X