Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-32958

Опубликовано: 23 мая 2022
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows an attacker with local command line interface access to gain the secret key, subsequently allowing them to generate valid session tokens for the web user interface (UI). With access to the web UI an attacker can access assets managed by the SRA installation and could compromise the installation.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:claroty:secure_remote_access:*:*:*:*:*:*:*:*
Версия от 3.0 (включая) до 3.2 (включая)

EPSS

Процентиль: 12%
0.0004
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-288
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.5
github
больше 3 лет назад

Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows an attacker with local command line interface access to gain the secret key, subsequently allowing them to generate valid session tokens for the web user interface (UI). With access to the web UI an attacker can access assets managed by the SRA installation and could compromise the installation.

EPSS

Процентиль: 12%
0.0004
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-288
NVD-CWE-noinfo