8.8
CVE-2021-38121
- EPSS 0.03%
- Published 28.08.2024 07:15:07
- Last modified 13.09.2024 18:04:16
- Source security@opentext.com
- Teams watchlist Login
- Open Login
Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices. This issue affects NetIQ Advance Authentication versions before 6.3.5.1
Data is provided by the National Vulnerability Database (NVD)
Microfocus ≫ Netiq Advanced Authentication Version < 6.3
Microfocus ≫ Netiq Advanced Authentication Version6.3 Update-
Microfocus ≫ Netiq Advanced Authentication Version6.3 Updatesp1
Microfocus ≫ Netiq Advanced Authentication Version6.3 Updatesp2
Microfocus ≫ Netiq Advanced Authentication Version6.3 Updatesp3
Microfocus ≫ Netiq Advanced Authentication Version6.3 Updatesp4
Microfocus ≫ Netiq Advanced Authentication Version6.3 Updatesp4_patch1
Microfocus ≫ Netiq Advanced Authentication Version6.3 Updatesp5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.076 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
security@opentext.com | 8.3 | 1.7 | 6 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
|
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.