Authentication bypass using an alternate path or channel in Secure Remote Access (SRA) Site - CVE-2021-32958
Published: June 30, 2021
Vulnerability identifier: #VU54469
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32958
CWE-ID: CWE-288
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to bypass authentication process.
The vulnerability exist due to improper implementation of the authentication process. A local user can gain the secret key, allowing them to generate valid session tokens for the web user interface (UI).
Affected software
Secure Remote Access (SRA) Site
How to mitigate CVE-2021-32958
Install updates from vendor's website.
Secure Remote Access (SRA) Site - update to 3.2.1