CVE Vulnerabilities

CVE-2021-38121

Inadequate Encryption Strength

Published: Aug 28, 2024 | Modified: Sep 13, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices.  This issue affects NetIQ Advance Authentication versions before 6.3.5.1

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

NameVendorStart VersionEnd Version
Netiq_advanced_authenticationMicrofocus*6.3 (excluding)
Netiq_advanced_authenticationMicrofocus6.3 (including)6.3 (including)
Netiq_advanced_authenticationMicrofocus6.3-sp1 (including)6.3-sp1 (including)
Netiq_advanced_authenticationMicrofocus6.3-sp2 (including)6.3-sp2 (including)
Netiq_advanced_authenticationMicrofocus6.3-sp3 (including)6.3-sp3 (including)
Netiq_advanced_authenticationMicrofocus6.3-sp4 (including)6.3-sp4 (including)
Netiq_advanced_authenticationMicrofocus6.3-sp4_patch1 (including)6.3-sp4_patch1 (including)
Netiq_advanced_authenticationMicrofocus6.3-sp5 (including)6.3-sp5 (including)

Potential Mitigations

References