PT-2021-19936 · Unknown · Archisteamfarm

Abrynos

·

Published

2021-07-26

·

Updated

2022-07-02

·

CVE-2021-32794

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ArchiSteamFarm versions prior to 5.1.2.4
Description ArchiSteamFarm is a C# application for idling Steam cards from multiple accounts simultaneously. A bug in the code for the POST /Api/ASF API endpoint, which updates the global ASF config, incorrectly removes the IPCPassword from the resulting config if not specified explicitly. This allows users to accidentally remove the IPCPassword security measure when updating the global ASF config, posing a security risk as unauthorized users may access the IPC interface. By default, ASF is configured to allow IPC access from localhost only, which should not affect the majority of users.
Recommendations For versions prior to 5.1.2.4, update to version 5.1.2.4 or later to resolve the issue. After updating, manually verify that the IPCPassword is specified and set it accordingly if it is not. As a temporary workaround, consider restricting access to the IPC interface to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32794
GHSA-WXX4-66C2-VJ2V

Affected Products

Archisteamfarm