PT-2021-2560 · Vmware · Vmware Carbon Black Cloud Workload Appliance
Egor Dimitrenko
·
Published
2021-04-01
·
Updated
2021-04-12
·
CVE-2021-21982
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
VMware Carbon Black Cloud Workload appliance versions 1.0.0 through 1.0.1
Description:
The issue is related to an authentication bypass vulnerability in the administrative interface of the VMware Carbon Black Cloud Workload appliance. This vulnerability may allow a malicious actor with network access to obtain a valid authentication token, resulting in the ability to view and alter administrative configuration settings. The vulnerability is related to deficiencies in the authentication procedure.
Recommendations:
For versions 1.0.0 and 1.0.1, update to a version newer than 1.0.1 to resolve the issue.
As a temporary workaround, consider restricting access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Carbon Black Cloud Workload Appliance