// For flags

CVE-2021-46434

 

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

EMQ X Dashboard V3.0.0 is affected by username enumeration in the "/api /v3/auth" interface. When a user login, the application returns different results depending on whether the account is correct, that allowed an attacker to determine if a given username was valid

EMQ X Dashboard versión V3.0.0, está afectado por una enumeración de nombres de usuario en la interfaz "/api /v3/auth". Cuando un usuario inicia sesión, la aplicación devuelve diferentes resultados dependiendo de si la cuenta es correcta, lo que permitía a un atacante determinar si un nombre de usuario dado era válido

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-01-24 CVE Reserved
  • 2022-03-28 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • 2024-11-01 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Emqx
Search vendor "Emqx"
Emqx
Search vendor "Emqx" for product "Emqx"
3.0.0
Search vendor "Emqx" for product "Emqx" and version "3.0.0"
-
Affected
* End Of Life in some or all products. Do not expect updates.