PT-2021-23760 · Unknown · Goautodial

Scott Tolley

·

Published

2021-12-07

·

Updated

2022-08-09

·

CVE-2021-43175

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GOautodial versions prior to commit 3c3a979
Description The issue concerns incorrect validation of the username and password parameters in the API router, allowing for successful authentication with any specified values.
Recommendations For versions prior to commit 3c3a979, update to a version that includes the fix made on October 13th, 2021, or later. As a temporary workaround, consider restricting access to the API router to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-43175

Affected Products

Goautodial