Authentication bypass using an alternate path or channel in Secure Remote Access (SRA) Site - CVE-2021-32958

 

Authentication bypass using an alternate path or channel in Secure Remote Access (SRA) Site - CVE-2021-32958

Published: June 30, 2021


Vulnerability identifier: #VU54469
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32958
CWE-ID: CWE-288
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass authentication process.  

The vulnerability exist due to improper implementation of the authentication process. A local user can gain the secret key, allowing them to generate valid session tokens for the web user interface (UI).


Affected software

Secure Remote Access (SRA) Site

How to mitigate CVE-2021-32958

Install updates from vendor's website.

Secure Remote Access (SRA) Site - update to 3.2.1

External References

Related Security Bulletins