Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE ID | N/A |
CWE ID | CWE-284 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #1 is available. |
Vulnerable software Subscribe |
SiteManager Server applications / Remote access servers, VPN |
Vendor |
This security advisory describes one low risk vulnerability.
Risk: Low
CVSSv3: 5.9 [CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C] [PCI]
CVE-ID: N/A
CWE-ID:
CWE-284 - Improper Access Control
Exploit availability: No
DescriptionThe vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote administrator can upload tampered firmware.
MitigationInstall updates from vendor's website.
Vulnerable software versionsSiteManager: before 9.4
CPE External linkshttps://www.tenable.com/security/research/tra-2021-06
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.