6.3
CVE-2021-45035
- EPSS 0.36%
- Veröffentlicht 23.09.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:31:50
- Quelle cve-coordination@incibe.es
- CVE-Watchlists
- Unerledigt
Velneo vClient Improper authentication
Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has access to the network to perform a MITM attack in order to obtain the user´s credentials.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.271 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| cve-coordination@incibe.es | 6.3 | 2.1 | 4.2 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
https://doc.velneo.com/v/29/velneo/notas-de-la-version#verificacion-de-certificados
https://velneo.es/publicacion-de-incidencia-de-seguridad-en-cve-cve-2021-45035/
https://www.incibe-cert.es/en/early-warning/security-advisories/velneo-vclient-improper-authentication
https://www.velneo.com/blog/nueva-revision-velneo-29-2