PT-2021-2560 · Vmware · Vmware Carbon Black Cloud Workload Appliance

Egor Dimitrenko

·

Published

2021-04-01

·

Updated

2021-04-12

·

CVE-2021-21982

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: VMware Carbon Black Cloud Workload appliance versions 1.0.0 through 1.0.1
Description: The issue is related to an authentication bypass vulnerability in the administrative interface of the VMware Carbon Black Cloud Workload appliance. This vulnerability may allow a malicious actor with network access to obtain a valid authentication token, resulting in the ability to view and alter administrative configuration settings. The vulnerability is related to deficiencies in the authentication procedure.
Recommendations: For versions 1.0.0 and 1.0.1, update to a version newer than 1.0.1 to resolve the issue. As a temporary workaround, consider restricting access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01986
CVE-2021-21982

Affected Products

Vmware Carbon Black Cloud Workload Appliance