8.8
CVE-2021-38121
- EPSS 0.03%
- Veröffentlicht 28.08.2024 07:15:07
- Zuletzt bearbeitet 13.09.2024 18:04:16
- Quelle security@opentext.com
- Teams Watchlist Login
- Unerledigt Login
Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices. This issue affects NetIQ Advance Authentication versions before 6.3.5.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microfocus ≫ Netiq Advanced Authentication Version < 6.3
Microfocus ≫ Netiq Advanced Authentication Version6.3 Update-
Microfocus ≫ Netiq Advanced Authentication Version6.3 Updatesp1
Microfocus ≫ Netiq Advanced Authentication Version6.3 Updatesp2
Microfocus ≫ Netiq Advanced Authentication Version6.3 Updatesp3
Microfocus ≫ Netiq Advanced Authentication Version6.3 Updatesp4
Microfocus ≫ Netiq Advanced Authentication Version6.3 Updatesp4_patch1
Microfocus ≫ Netiq Advanced Authentication Version6.3 Updatesp5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.076 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
security@opentext.com | 8.3 | 1.7 | 6 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
|
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.