← Back

CVE-2021-27215

nvd nist
Published: Mar 3, 2021Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7, and 10.x before 10.1 p4. The Web Interfaces (Admin, Userweb, Sidechannel) can use different methods to perform the authentication of a user. A specific authentication method during login does not check the provided data (when a certain manipulation occurs) and returns OK for any authentication request. This allows an attacker to login to the admin panel as a user of his choice, e.g., the root user (with highest privileges) or even a non-existing user.

Affected (32)

Products: Genua: Genuagate
1 product
Genuagate
Configuration A
32 vulnerable
Vulnerable SoftwareAffected Versions
Genua
Up to 9.0
From 10.0 to 10.1
Version 10.1
Version 10.1 p1
Version 10.1 p2
Version 10.1 p3
Version 9.0
Version 9.0 p10
Version 9.0 p11
Version 9.0 p12
Version 9.0 p13
Version 9.0 p14
Version 9.0 p15
Version 9.0 p16
Version 9.0 p17
Version 9.0 p18
Version 9.0 p1
Version 9.0 p2
Version 9.0 p3
Version 9.0 p4
Version 9.0 p5
Version 9.0 p6
Version 9.0 p7
Version 9.0 p8
Version 9.0 p9
Version 9.6.0
Version 9.6.0 p1
Version 9.6.0 p2
Version 9.6.0 p3
Version 9.6.0 p4
Version 9.6.0 p5
Version 9.6.0 p6

References (6)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.