CVE-2014-4198: Bssys Rbs Bs-Client. Retail Client

Critical severity, CVSS 9.1. EPSS: 1.3% chance of exploitation in the next 30 days.

A Two-Factor Authentication Bypass Vulnerability exists in BS-Client Private Client 2.4 and 2.5 via an XML request that neglects the use of ADPswID and AD parameters, which could let a malicious user access privileged function.

Affected products

  • Bssys Rbs Bs-Client. Retail Client: version 2.4 only; version 2.5 only

Published 2020-02-13. Last modified 2026-06-17.