CVE-2021-44793
Information Leakege via Unauthorized Access in Single Connect
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to access the device configuration page and export the data to an external file. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information including the database credentials. Since the database runs with high privileges it is possible to execute commands with the attained credentials.
Single Connect no lleva a cabo una comprobación de autorización cuando se usa el módulo sc-reports-ui". Un atacante remoto podría aprovechar esta vulnerabilidad para acceder a la página de configuración del dispositivo y exportar los datos a un archivo externo. La explotación de esta vulnerabilidad podría permitir a un atacante remoto obtener información confidencial, incluyendo las credenciales de la base de datos. Dado que la base de datos es ejecutada con altos privilegios, es posible ejecutar comandos con las credenciales obtenidas
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-12-10 CVE Reserved
- 2022-01-27 CVE Published
- 2024-09-17 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
- CAPEC-569: Collect Data as Provided by Users
References (1)
URL | Tag | Source |
---|---|---|
https://www.usom.gov.tr/bildirim/tr-22-0093 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Krontech Search vendor "Krontech" | Single Connect Search vendor "Krontech" for product "Single Connect" | < 2.16 Search vendor "Krontech" for product "Single Connect" and version " < 2.16" | - |
Affected
|