CVE-2025-34143 Details
Description
An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login as the privileged internal SYSTEM user by manipulating the username field. The SYSTEM account does not require a password, enabling attackers with network access to the login page to obtain elevated access. Once authenticated, an attacker could achieve remote code execution by modifying Jython scripts within the application. This issue was resolved by introducing stricter validation logic to exclude internal accounts from public authentication workflows in version MP-4583.
A vulnerability allowing authentication bypass has been identified in ETQ Reliance on the CG (legacy) platform. This issue arises from improper input validation in the login process, which allows manipulation of the username field to gain access as the internal SYSTEM user. The SYSTEM account, which does not require a password, can be exploited by attackers with network access to the login page. Once authenticated, attackers can achieve remote code execution by modifying Jython scripts within the application. This vulnerability has been addressed in version MP-4583 by implementing stricter validation to prevent internal accounts from being authenticated through public workflows.
ETQ has released a patch in version MP-4583, which is available to on-premises customers. The patch has been deployed to hosted customers.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 22, 2025CISA-ADP
Assessed Jul 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ETQ Reliance | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | CVE Modified | [email protected] |
| Jul 22, 2025 | New CVE Received | [email protected] |
Volerion