6.5
CVE-2021-33831
- EPSS 2.02%
- Veröffentlicht 07.09.2021 06:15:07
- Zuletzt bearbeitet 21.11.2024 06:09:38
- CVE-Watchlists
- Unerledigt
api/account/register in the TH Wildau COVID-19 Contact Tracing application through 2021-09-01 has Incorrect Access Control. An attacker can interfere with tracing of infection chains by creating 500 random users within 2500 seconds.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Th-wildau ≫ Covid-19 Contact Tracing Version <= 2021-09-01
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.02% | 0.785 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:N/A:P
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
https://github.com/lanmarc77/CVE-2021-33831
https://www.th-wildau.de/studieren-weiterbilden/neuigkeiten-und-veranstaltungen/corona/