What the vulnerability does
01Description
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
Explanation of Vulnerability in Simple Terms
The Secure Card Gateway for ePay Paycenter lacks proper authorization checks, allowing unauthenticated attackers to modify data or disrupt service. An attacker can send network requests without credentials to trigger unauthorized changes or cause temporary unavailability. This affects all versions up to 1.0.32. Site administrators should update immediately when a patch becomes available.
What an attacker can do
Modify payment gateway data or cause temporary service disruption without authentication.
Potential impact on your site
Payment processing may be disrupted or transaction data altered without warning or audit trail.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities