PT-2021-16633 · Unknown+1 · Kme Module+1

Hard

·

Published

2021-07-08

·

Updated

2021-07-12

·

CVE-2021-25442

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: KME module prior to KCS version 1.39
Description: The issue is related to improper MDM policy management in the KME module, allowing MDM users to bypass Knox Manage authentication.
Recommendations: For versions prior to KCS version 1.39, update to version 1.39 or later to resolve the issue.

Fix

Improper Authentication

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25442

Affected Products

Kme Module
Knox Manage