Authorization bypass through user-controlled key in Industrial Edge Management - CVE-2021-37184

 

Authorization bypass through user-controlled key in Industrial Edge Management - CVE-2021-37184

Published: September 16, 2021


Vulnerability identifier: #VU56643
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37184
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exist due to insufficient access authorization. A remote attacker can change the password of any user in the system under certain circumstances and impersonate any valid user on an affected system.


Affected software

Industrial Edge Management

How to mitigate CVE-2021-37184

Install updates from vendor's website.

Industrial Edge Management - update to 1.3

External References

Related Security Bulletins