CVE Vulnerabilities

CVE-2021-42701

Modification of Assumed-Immutable Data (MAID)

Published: Nov 05, 2021 | Modified: Nov 09, 2021
CVSS 3.x
6.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An attacker could prepare a specially crafted project file that, if opened, would attempt to connect to the cloud and trigger a man in the middle (MiTM) attack. This could allow an attacker to obtain credentials and take over the user’s cloud account.

Weakness

The product does not properly protect an assumed-immutable element from being modified by an attacker.

Affected Software

Name Vendor Start Version End Version
Daqfactory Azeotech * 18.1 (including)
Daqfactory Azeotech 18.1-build_2347 (including) 18.1-build_2347 (including)

Potential Mitigations

References