Vulnerability CVE-2021-35050


Published: 2021-06-25

Description:
User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the CommandPost, these values could be decoded and used to login to the application. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.3. This vulnerability has been addressed in version 9.3.3 and subsequent versions.

Type:

CWE-522

(Insufficiently Protected Credentials)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Fidelissecurity -> Deception 
Fidelissecurity -> Network 

 References:
https://support.fidelissecurity.com/hc/en-us/categories/360001842694-Advisories-News-and-Policies

Copyright 2021, cxsecurity.com

 

Back to Top