PT-2021-20811 · Fidelis · Fidelis Network/Deception

B0Yd

+1

·

Published

2021-06-25

·

Updated

2021-09-14

·

CVE-2021-35048

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Fidelis Network and Deception versions prior to 9.3.7 Fidelis Network and Deception version 9.4
Description: The issue allows for unauthenticated SQL injection through the web interface, potentially leading to exposure of authentication tokens in some versions of the software.
Recommendations: For versions prior to 9.3.7, update to version 9.3.7 or later to address the issue. For version 9.4, apply the available patch or update to resolve the vulnerability.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-35048

Affected Products

Fidelis Network/Deception