9.8
CVE-2021-28123
- EPSS 0.84%
- Veröffentlicht 02.04.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:59:07
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Undocumented Default Cryptographic Key Vulnerability in Cohesity DataPlatform version 6.3 prior 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. The ssh key can provide an attacker access to the linux system in the affected version.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cohesity ≫ Cohesity Dataplatform Version >= 6.3 < 6.3.1g
Cohesity ≫ Cohesity Dataplatform Version >= 6.4 < 6.4.1c
Cohesity ≫ Cohesity Dataplatform Version >= 6.5.1 < 6.5.1b
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.84% | 0.725 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-1188 Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.