CVE Vulnerabilities

CVE-2021-45917

Improper Authentication

Published: Jan 03, 2022 | Modified: Jan 07, 2022
CVSS 3.x
9
CRITICAL
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
7.7 HIGH
AV:A/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The server-request receiver function of Shockwall system has an improper authentication vulnerability. An authenticated attacker of an agent computer within the local area network can use the local registry information to launch server-side request forgery (SSRF) attack on another agent computer, resulting in arbitrary code execution for controlling the system or disrupting service.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Network_computer_terminal_protection_system_firmware Sun_moon_jingyao * 7.20.0401 (excluding)

Potential Mitigations

References