CVE-2021-22850
19.01.2021, 10:15
HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.Enginsight
Vendor | Product | Version |
---|---|---|
hgiga | oaklouds_portal | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-732 - Incorrect Permission Assignment for Critical ResourceThe product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
- CWE-306 - Missing Authentication for Critical FunctionThe product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.