... and the system accepts the old format? Wouldn't that be the actual problem here? Is there something wrong with the old format that caused a security weakness?
>Using either of the two methods, with the HMAC check completely bypassed, you’ve reduced the security of this construction to unauthenticated AES-CBC mode, which is vulnerable to a Padding Oracle Attack.
Well was this particular system actually vulnerable to a padding oracle attack?
I hate these security writeups that prime the reader but never actually get to the punch line. If something has a security weakness you should explicitly state exactly what it is. Don't leave it to the reader to figure it out. If it turns out that there was no actual issue then you are being misleading by the implication that there was.