Vulnerability record · CVE-2016-7836 · published 9 June 2017
CVE-2016-7836: SKYSEA Client View improper authentication enables remote code execution
Skygroup · Skysea Client View
SKYSEA Client View Ver.11.221.03 and earlier contains an improper authentication flaw (CWE-287) in how the management console program processes authentication on the TCP connection. Because the authentication check can be bypassed, an unauthenticated remote party can reach code execution on affected hosts. The record does not list specific affected platforms or deployment topologies beyond the version range.
Description
SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, plus confirmed exploitation via CISA KEV, makes this an urgent patch-or-isolate case.
What it is
SKYSEA Client View Ver.11.221.03 and earlier contains an improper authentication flaw (CWE-287) in how the management console program processes authentication on the TCP connection. Because the authentication check can be bypassed, an unauthenticated remote party can reach code execution on affected hosts. The record does not list specific affected platforms or deployment topologies beyond the version range.
Impact
An attacker gains remote code execution on the machine running the vulnerable SKYSEA Client View component, with high impact to confidentiality, integrity and availability. This can lead to full host compromise and use of the host as a foothold in the managed environment.
Attack surface
Reachable over the network via the TCP connection handled by the management console program, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.
Exploitation
CVE-2016-7836 was added to CISA KEV on 2025-10-14, indicating known exploitation, and EPSS shows a 30-day probability of 0.1938 (97.2nd percentile). A reference is tagged Exploit, and CISA KEV does not list known ransomware campaign use.
What to do
- Upgrade SKYSEA Client View to a version later than Ver.11.221.03 per the vendor advisory; patch first.
- If upgrading is not possible, restrict network access to the management console TCP service to trusted management hosts only, or discontinue use of the product as CISA advises.
- Apply the vendor's mitigation guidance referenced in the CISA KEV required action and BOD 22-01 guidance for cloud services.
- Segment or isolate hosts running the affected management console so a compromise cannot pivot into the wider managed estate.
- Verify the version of every deployed SKYSEA Client View instance to find remaining vulnerable endpoints.
Detection
- Monitor network traffic to the management console TCP port for connections from unexpected or unauthorized source hosts.
- Alert on unexpected process creation or child processes spawned by the SKYSEA Client View management console service.
- Review host and application logs for authentication failures or anomalous connection handling on the management console service.
- Hunt for signs of post-exploitation activity on hosts running the affected version, such as new services, scheduled tasks or outbound connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-7836 to the Known Exploited Vulnerabilities catalog on 14 October 2025 as "SKYSEA Client View Improper Authentication Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 4 November 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/95062 | Third Party AdvisoryVDB Entry |
| http://www.skyseaclientview.net/news/161221/ | Vendor Advisory |
| https://jvn.jp/en/jp/JVN84995847/index.html | Third Party AdvisoryVDB Entry |
| https://www.skygroup.jp/security-info/170308.html | ExploitTechnical DescriptionThird Party Advisory |
| http://www.securityfocus.com/bid/95062 | Third Party AdvisoryVDB Entry |
| http://www.skyseaclientview.net/news/161221/ | Vendor Advisory |
| https://jvn.jp/en/jp/JVN84995847/index.html | Third Party AdvisoryVDB Entry |
| https://www.skygroup.jp/security-info/170308.html | ExploitTechnical DescriptionThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7836 | US Government Resource |
Track CVE-2016-7836 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-7836), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.