CVE-2021-27215
03.03.2021, 16:15
An issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7, and 10.x before 10.1 p4. The Web Interfaces (Admin, Userweb, Sidechannel) can use different methods to perform the authentication of a user. A specific authentication method during login does not check the provided data (when a certain manipulation occurs) and returns OK for any authentication request. This allows an attacker to login to the admin panel as a user of his choice, e.g., the root user (with highest privileges) or even a non-existing user.Enginsight
Vendor | Product | Version |
---|---|---|
genua | genuagate | 𝑥 ≤ 9.0 |
genua | genuagate | 10.0 ≤ 𝑥 ≤ 10.1 |
genua | genuagate | 9.0 |
genua | genuagate | 9.0:p1 |
genua | genuagate | 9.0:p10 |
genua | genuagate | 9.0:p11 |
genua | genuagate | 9.0:p12 |
genua | genuagate | 9.0:p13 |
genua | genuagate | 9.0:p14 |
genua | genuagate | 9.0:p15 |
genua | genuagate | 9.0:p16 |
genua | genuagate | 9.0:p17 |
genua | genuagate | 9.0:p18 |
genua | genuagate | 9.0:p2 |
genua | genuagate | 9.0:p3 |
genua | genuagate | 9.0:p4 |
genua | genuagate | 9.0:p5 |
genua | genuagate | 9.0:p6 |
genua | genuagate | 9.0:p7 |
genua | genuagate | 9.0:p8 |
genua | genuagate | 9.0:p9 |
genua | genuagate | 9.6.0 |
genua | genuagate | 9.6.0:p1 |
genua | genuagate | 9.6.0:p2 |
genua | genuagate | 9.6.0:p3 |
genua | genuagate | 9.6.0:p4 |
genua | genuagate | 9.6.0:p5 |
genua | genuagate | 9.6.0:p6 |
genua | genuagate | 10.1 |
genua | genuagate | 10.1:p1 |
genua | genuagate | 10.1:p2 |
genua | genuagate | 10.1:p3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References