CVE Vulnerabilities

CVE-2021-38121

Inadequate Encryption Strength

Published: Aug 28, 2024 | Modified: Sep 13, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices.  This issue affects NetIQ Advance Authentication versions before 6.3.5.1

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
Netiq_advanced_authentication Microfocus * 6.3 (excluding)
Netiq_advanced_authentication Microfocus 6.3 (including) 6.3 (including)
Netiq_advanced_authentication Microfocus 6.3-sp1 (including) 6.3-sp1 (including)
Netiq_advanced_authentication Microfocus 6.3-sp2 (including) 6.3-sp2 (including)
Netiq_advanced_authentication Microfocus 6.3-sp3 (including) 6.3-sp3 (including)
Netiq_advanced_authentication Microfocus 6.3-sp4 (including) 6.3-sp4 (including)
Netiq_advanced_authentication Microfocus 6.3-sp4_patch1 (including) 6.3-sp4_patch1 (including)
Netiq_advanced_authentication Microfocus 6.3-sp5 (including) 6.3-sp5 (including)

Potential Mitigations

References