PT-2021-3778 · Vmware · Vmware Workspace One Access+1

Published

2021-08-05

·

Updated

2021-09-09

·

CVE-2021-22003

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware Workspace ONE Access and Identity Manager (affected versions not specified)
Description The issue is related to the unintentional provision of a login interface on port 7443, which may allow a malicious actor with network access to attempt user enumeration or brute force the login endpoint. The practicality of such attempts depends on the lockout policy configuration and password complexity for the target account. Additionally, there is a concern about the transmission of data over an insecure primary channel, which could enable a remote attacker to bypass existing security restrictions using a brute force attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04034
CVE-2021-22003

Affected Products

Vmware Identity Manager
Vmware Workspace One Access