Improper Authentication in Enterprise NFV Infrastructure Software - CVE-2021-34746

 

Improper Authentication in Enterprise NFV Infrastructure Software - CVE-2021-34746

Published: September 2, 2021


Vulnerability identifier: #VU56260
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34746
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests in the TACACS+ authentication, authorization and accounting (AAA) feature. A remote attacker can inject parameters into an authentication request, bypass authentication and log in as an administrator to the affected device.


Affected software

Enterprise NFV Infrastructure Software

How to mitigate CVE-2021-34746

Install updates from vendor's website.

Enterprise NFV Infrastructure Software - update to 4.6.1

External References

Related Security Bulletins