Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40067

Опубликовано: 16 сент. 2021
Источник: nvd
CVSS3: 6.8
CVSS2: 4.9
EPSS Низкий

Описание

The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v12.14.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:netmotionsoftware:mobility:*:*:*:*:*:*:*:*
Версия до 12.14 (исключая)

EPSS

Процентиль: 37%
0.00158
Низкий

6.8 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-732

Связанные уязвимости

github
больше 3 лет назад

The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v12.14.

EPSS

Процентиль: 37%
0.00158
Низкий

6.8 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-732