PT-2021-16633 · Unknown+1 · Kme Module+1
Hard
·
Published
2021-07-08
·
Updated
2021-07-12
·
CVE-2021-25442
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
KME module prior to KCS version 1.39
Description:
The issue is related to improper MDM policy management in the KME module, allowing MDM users to bypass Knox Manage authentication.
Recommendations:
For versions prior to KCS version 1.39, update to version 1.39 or later to resolve the issue.
Fix
Improper Authentication
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kme Module
Knox Manage