Authorization bypass through user-controlled key in Industrial Edge Management - CVE-2021-37184
Published: September 16, 2021
Vulnerability identifier: #VU56643
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37184
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exist due to insufficient access authorization. A remote attacker can change the password of any user in the system under certain circumstances and impersonate any valid user on an affected system.
Affected software
Industrial Edge Management
How to mitigate CVE-2021-37184
Install updates from vendor's website.
Industrial Edge Management - update to 1.3