Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknets NEO V4.0R1.0 to V9.0R2.0 allows an attacker to create malicious AppSuite applications.
The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.