PT-2021-22451 · Capture · Capture
Jdhwpgmbca
·
Published
2021-09-07
·
Updated
2022-08-05
·
CVE-2021-39196
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
pcapture versions prior to 3.12
Description
The issue allows an authenticated but unprivileged user to use the REST API to capture and download packets with no capture filter and without adequate permissions. This is significant because capture filters can limit the scope of information that a user can see in the data captures. If no filter is present, all data on the local network segment where the program is running can be captured and downloaded.
Recommendations
For versions prior to 3.12, upgrade to version 3.12 or greater to resolve the issue. There is no workaround, and upgrading is the only solution to fix the problem.
Fix
Improper Authentication
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Capture