#VU56643 Authorization bypass through user-controlled key in Industrial Edge Management - CVE-2021-37184

 

#VU56643 Authorization bypass through user-controlled key in Industrial Edge Management - CVE-2021-37184

Published: September 16, 2021


Vulnerability identifier: #VU56643
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2021-37184
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Industrial Edge Management
Software vendor:
Siemens

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exist due to insufficient access authorization. A remote attacker can change the password of any user in the system under certain circumstances and impersonate any valid user on an affected system.


Remediation

Install updates from vendor's website.

External links