Executive brief
Vidco Software VOC TESTER, a tool used for testing and diagnostics, contains a security flaw that allows users to bypass authorization. By manipulating specific keys or navigating directly to restricted areas of the application, an unauthorized user could access sensitive information they are not supposed to see. This could lead to the exposure of confidential diagnostic data or system configurations.
Technical details
An authorization bypass vulnerability (CWE-639) exists in Vidco Software VOC TESTER versions prior to 12.41.0. The flaw stems from the application's failure to properly validate user-controlled keys, allowing an attacker to perform 'forceful browsing' to access restricted resources. A local attacker with low privileges can exploit this to bypass intended access controls and view sensitive data. The vulnerability is addressed in version 12.41.0.
Affected products
- Vidco Software VOC TESTER before 12.41.0
Timeline
- 2025-07-18: advisory: Initial publication of the vulnerability details.
- 2026-06-01: other: Last modified date in NVD records.