Improper Authentication in Paragon Active Assurance Control Center - CVE-2021-0232

 

Improper Authentication in Paragon Active Assurance Control Center - CVE-2021-0232

Published: April 19, 2021


Vulnerability identifier: #VU52322
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0232
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote attacker with specific information about the deployment can mimic an already registered Test Agent and access its configuration including associated inventory details.


Affected software

Paragon Active Assurance Control Center

How to mitigate CVE-2021-0232

Install updates from vendor's website.

Paragon Active Assurance Control Center - addressed in versions 2.35.6, 2.36.2

External References

Related Security Bulletins