Executive brief
4C Strategies Exonaut, a software suite used for organizational resilience and crisis management, contains a security flaw where system permissions were not correctly restricted. This could allow unauthorized individuals to access or modify sensitive information within the application. Organizations should update to version 22.4 or later to ensure their data and operational workflows are properly protected.
Technical details
A vulnerability classified as Incorrect Default Permissions (CWE-276) exists in 4C Strategies Exonaut for Windows prior to version 22.4. The flaw allows for insecure permissions within the application environment. According to the CVSS vector, the vulnerability is network-accessible and requires no authentication or user interaction, potentially allowing an attacker to read or modify data (partial impact to confidentiality and integrity). The issue has been addressed in version 22.4.
Affected products
- 4C Strategies Exonaut before 22.4 (Windows)
Timeline
- 2025-08-05: disclosed: Initial discovery/gist creation by Justin Hocquel
- 2025-08-06: advisory: NVD publication date