PT-2021-17329 · Genua · Genugate

Armin Stock

·

Published

2021-03-01

·

Updated

2022-07-12

·

CVE-2021-27215

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: genua genugate versions 9.0 Z before p19 genua genugate versions 9.1.x through 9.6.x before 9.6 p7 genua genugate versions 10.x before 10.1 p4
Description: An issue was discovered in the Web Interfaces of genua genugate, where a specific authentication method during login does not check the provided data and returns OK for any authentication request, allowing an attacker to login to the admin panel as a user of their choice, including the root user or even a non-existing user. This is possible due to a lack of proper validation of the provided data when a certain manipulation occurs.
Recommendations: For genua genugate versions 9.0 Z before p19, update to version 9.0 Z p19 or later. For genua genugate versions 9.1.x through 9.6.x before 9.6 p7, update to version 9.6 p7 or later. For genua genugate versions 10.x before 10.1 p4, update to version 10.1 p4 or later. As a temporary workaround, consider restricting access to the Web Interfaces (Admin, Userweb, Sidechannel) until a patch is available.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27215

Affected Products

Genugate