PT-2021-22451 · Capture · Capture

Jdhwpgmbca

·

Published

2021-09-07

·

Updated

2022-08-05

·

CVE-2021-39196

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions pcapture versions prior to 3.12
Description The issue allows an authenticated but unprivileged user to use the REST API to capture and download packets with no capture filter and without adequate permissions. This is significant because capture filters can limit the scope of information that a user can see in the data captures. If no filter is present, all data on the local network segment where the program is running can be captured and downloaded.
Recommendations For versions prior to 3.12, upgrade to version 3.12 or greater to resolve the issue. There is no workaround, and upgrading is the only solution to fix the problem.

Fix

Improper Authentication

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2021-39196
GHSA-3R67-FXPR-P2QX

Affected Products

Capture