PT-2022-12298 · Velneo · Velneo Vclient

Jesús Ródenas Huerta

+1

·

Published

2022-11-28

·

Updated

2024-09-16

·

CVE-2021-45036

CVSS v3.1

8.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Velneo vClient version 28.1.3
Description The issue allows an attacker with knowledge of the victim's username and hashed password to spoof the victim's id against the server.
Recommendations For Velneo vClient version 28.1.3, consider restricting access to sensitive operations that rely on the victim's id until a patch is available. As a temporary workaround, ensure that the server-side validation of user identities is enhanced to prevent spoofing. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2021-45036

Affected Products

Velneo Vclient