PT-2021-22791 · Mobility · Mobility

Published

2021-09-16

·

Updated

2021-11-29

·

CVE-2021-40067

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mobility versions prior to 12.14
Description The access controls on the Mobility read-write API improperly validate user access permissions. This API is disabled by default, but if manually enabled, attackers with network access to the API and valid credentials can read and write data to it, regardless of access control group membership settings.
Recommendations For versions prior to 12.14, update to Mobility version 12.14 to resolve the issue. As a temporary workaround, consider disabling the Mobility read-write API until the update is applied. Restrict access to the API to minimize the risk of exploitation.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40067

Affected Products

Mobility