A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.
https://www.cisa.gov/news-events/ics-advisories/icsa-23-108-02