EXPOSURES › CVE-2016-7836
CVE-2016-7836
HIGH ⌖ ON CISA KEV · EXPLOITEDSKYSEA Client View allowed remote code execution due to an unpatched authentication flaw.
SKYSEA Client View, a product from SKYSEA, had an unpatched vulnerability that enabled remote code execution through its TCP connection with the management console. This flaw was actively exploited in the wild, leading to potential remote code execution without proper authentication.
Shame score — Active exploitation in the wild without a patch, posing a severe risk to DIB organizations.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.