PT-2021-5423 · Unknown · Team Password Manager

Stefan Walter

·

Published

2021-10-17

·

Updated

2021-11-23

·

CVE-2021-44037

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Team Password Manager versions prior to 10.135.236
Description The issue is related to an insufficient password reset mechanism in the Team Password Manager application. Exploitation of this issue may allow a remote attacker to gain unauthorized access to protected information by resetting passwords.
Recommendations For versions prior to 10.135.236, update to version 10.135.236 or later to resolve the issue. As a temporary workaround, consider restricting access to the password reset feature until a patch is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-06266
CVE-2021-44037

Affected Products

Team Password Manager