Executive brief
Argus Technology's BILGER software contains a security flaw that can lead to the unintended exposure of sensitive information. An attacker can manipulate message identifiers to access data that should otherwise be protected. This could result in the unauthorized disclosure of confidential business or system information, potentially compromising privacy and operational security.
Technical details
A vulnerability classified as CWE-201 (Insertion of Sensitive Information Into Sent Data) exists in Argus Technology Inc. BILGER versions prior to 2.4.9. The flaw allows a remote attacker to choose or manipulate message identifiers, leading to the exposure of sensitive data within transmitted messages. The attack can be carried out over the network without authentication or user interaction. Successful exploitation results in high confidentiality impact as sensitive information is leaked to unauthorized parties. Users are advised to upgrade to version 2.4.9 or later to remediate this issue.
Affected products
- Argus Technology Inc. BILGER before 2.4.9
Timeline
- 2025-12-02: advisory: Initial publication of the vulnerability advisory.