PT-2021-20357 · Etinet · Etinet Backbox E4.09
Published
2021-06-25
·
Updated
2022-12-20
·
CVE-2021-33895
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ETINET BACKBOX E4.09 version 22SEP2020
ETINET BACKBOX H4.09 version T0954V04^AAO
Description:
The issue arises from the mismanagement of password access control in ETINET BACKBOX. When a user logs in to the Backbox UI application using the User ID of the process running BBSV, the system procedure
USER AUTHENTICATE returns 0, indicating no error, if the user is not running the XYGate application. This leads to BBSV assuming the password is correct.Recommendations:
For ETINET BACKBOX E4.09 version 22SEP2020, update to version E4.10-19OCT2022, which includes the hotfix FIXPAK-19OCT-2022.
For ETINET BACKBOX H4.09 version T0954V04^AAO, at the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Etinet Backbox E4.09