9.8

CVE-2021-27215

Exploit
An issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7, and 10.x before 10.1 p4. The Web Interfaces (Admin, Userweb, Sidechannel) can use different methods to perform the authentication of a user. A specific authentication method during login does not check the provided data (when a certain manipulation occurs) and returns OK for any authentication request. This allows an attacker to login to the admin panel as a user of his choice, e.g., the root user (with highest privileges) or even a non-existing user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GenuaGenuagate Version <= 9.0
GenuaGenuagate Version >= 10.0 <= 10.1
GenuaGenuagate Version9.0 Update-
GenuaGenuagate Version9.0 Updatep1
GenuaGenuagate Version9.0 Updatep10
GenuaGenuagate Version9.0 Updatep11
GenuaGenuagate Version9.0 Updatep12
GenuaGenuagate Version9.0 Updatep13
GenuaGenuagate Version9.0 Updatep14
GenuaGenuagate Version9.0 Updatep15
GenuaGenuagate Version9.0 Updatep16
GenuaGenuagate Version9.0 Updatep17
GenuaGenuagate Version9.0 Updatep18
GenuaGenuagate Version9.0 Updatep2
GenuaGenuagate Version9.0 Updatep3
GenuaGenuagate Version9.0 Updatep4
GenuaGenuagate Version9.0 Updatep5
GenuaGenuagate Version9.0 Updatep6
GenuaGenuagate Version9.0 Updatep7
GenuaGenuagate Version9.0 Updatep8
GenuaGenuagate Version9.0 Updatep9
GenuaGenuagate Version9.6.0 Update-
GenuaGenuagate Version9.6.0 Updatep1
GenuaGenuagate Version9.6.0 Updatep2
GenuaGenuagate Version9.6.0 Updatep3
GenuaGenuagate Version9.6.0 Updatep4
GenuaGenuagate Version9.6.0 Updatep5
GenuaGenuagate Version9.6.0 Updatep6
GenuaGenuagate Version10.1 Update-
GenuaGenuagate Version10.1 Updatep1
GenuaGenuagate Version10.1 Updatep2
GenuaGenuagate Version10.1 Updatep3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.71% 0.721
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.