Lucene search

K
cvelistTwcertCVELIST:CVE-2021-32541
HistoryMay 28, 2021 - 12:00 a.m.

CVE-2021-32541 SysJust CTS Web - Broken Access Control

2021-05-2800:00:00
twcert
www.cve.org
5
cve-2021-32541
sysjust
cts web
broken access control
authentication
session management
remote attackers
unauthenticated
username
account logout
service access

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

61.6%

The CTS Web transaction system related to authentication and session management is implemented incorrectly, which allows remote unauthenticated attackers can send a large number of valid usernames, and force those logged-in account to log out, causing the user to be unable to access the services

CNA Affected

[
  {
    "product": " CTS Web",
    "vendor": "SysJust",
    "versions": [
      {
        "lessThanOrEqual": "released 2021.3.25",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

61.6%

Related for CVELIST:CVE-2021-32541