PT-2021-3261 · Unknown · Veritystream Msow Solutions
Marbaṩ
·
Published
2021-04-29
·
Updated
2022-07-12
·
CVE-2021-32077
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
VerityStream MSOW Solutions versions prior to 3.1.1
Description
The issue allows an anonymous internet user to discover Social Security Number (SSN) values via a brute-force attack on a search field. This is because the last four SSN digits are part of the supported combination of search selectors, which can disclose doctors' and nurses' social security numbers and personally identifiable information (PII). The vulnerability is related to insufficient protection of service data in the registration and authentication system.
Recommendations
For versions prior to 3.1.1, update to version 3.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the search field to minimize the risk of exploitation. Additionally, limit the use of SSN digits as part of the search selectors to prevent brute-force attacks.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veritystream Msow Solutions