PT-2021-17755 · Express+1 · Express+1
Rashley-Iqtop
·
Published
2021-03-10
·
Updated
2022-07-12
·
CVE-2021-28122
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Open5GS versions 2.1.3 through 2.2.x before 2.2.1
Description:
A request-validation issue was discovered in the WebUI component, allowing an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber database. For example, new administrative users can be added. The issue occurs because Express is not set up to require authentication.
Recommendations:
For Open5GS versions 2.1.3 through 2.2.x before 2.2.1, consider setting up Express to require authentication for the WebUI component to prevent unauthorized access to the subscriber database.
As a temporary workaround, consider restricting access to the WebUI component until a patch is available.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Express
Open5Gs