CVE-2018-25129 describes multiple Insecure Direct Object Reference (IDOR) vulnerabilities in SOCA Access Control System 180612. These flaws allow unauthenticated attackers to access sensitive user credentials, including password hashes and PINs, via unprotected endpoints like Get_Permissions_From_DB.php and Ac10_ReadSortCard. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity, leading to a high impact on confidentiality. There is currently no public exploit code available, nor is there evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SOCA Technology Co., Ltd | SOCA Access Control System | 141007, 170000, 180612CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.