PT-2021-20814 · Fidelis · Fidelis Network/Deception
B0Yd
+1
·
Published
2021-06-25
·
Updated
2022-08-12
·
CVE-2021-35050
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Fidelis Network and Deception versions prior to 9.3.3
Description:
The issue concerns user credentials being stored in a recoverable format within the system. If an attacker gains access to the CommandPost, they could decode and use these credentials to login to the application.
Recommendations:
For versions prior to 9.3.3, update to version 9.3.3 or a subsequent version to resolve the issue. As a temporary workaround, consider restricting access to the CommandPost to minimize the risk of exploitation.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fidelis Network/Deception