PT-2021-17329 · Genua · Genugate
Armin Stock
·
Published
2021-03-01
·
Updated
2022-07-12
·
CVE-2021-27215
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
genua genugate versions 9.0 Z before p19
genua genugate versions 9.1.x through 9.6.x before 9.6 p7
genua genugate versions 10.x before 10.1 p4
Description:
An issue was discovered in the Web Interfaces of genua genugate, where a specific authentication method during login does not check the provided data and returns OK for any authentication request, allowing an attacker to login to the admin panel as a user of their choice, including the root user or even a non-existing user. This is possible due to a lack of proper validation of the provided data when a certain manipulation occurs.
Recommendations:
For genua genugate versions 9.0 Z before p19, update to version 9.0 Z p19 or later.
For genua genugate versions 9.1.x through 9.6.x before 9.6 p7, update to version 9.6 p7 or later.
For genua genugate versions 10.x before 10.1 p4, update to version 10.1 p4 or later.
As a temporary workaround, consider restricting access to the Web Interfaces (Admin, Userweb, Sidechannel) until a patch is available.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Genugate