CVE-2021-40066
16.09.2021, 12:15
The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v11.76 and Mobility v12.14.Enginsight
Vendor | Product | Version |
---|---|---|
netmotionsoftware | mobility | 𝑥 < 11.76 |
netmotionsoftware | mobility | 12.00 ≤ 𝑥 < 12.14 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration