CVE-2021-45036

Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:velneo:vclient:28.1.3:*:*:*:*:*:*:*

History

16 Sep 2024, 18:15

Type Values Removed Values Added
Summary (en) Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server. (en) Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server.

09 Nov 2023, 16:15

Type Values Removed Values Added
References
  • {'url': 'https://www.incibe-cert.es/en/early-warning/security-advisories/velneo-vclient-improper-authentication-0', 'name': 'https://www.incibe-cert.es/en/early-warning/security-advisories/velneo-vclient-improper-authentication-0', 'tags': ['Third Party Advisory'], 'refsource': 'CONFIRM'}
  • () https://www.incibe.es/en/incibe-cert/notices/aviso/velneo-vclient-improper-authentication-0 -
Summary Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server. Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server.

21 Jul 2023, 16:45

Type Values Removed Values Added
CWE CWE-290 CWE-287

Information

Published : 2022-11-28 16:15

Updated : 2024-09-16 18:15


NVD link : CVE-2021-45036

Mitre link : CVE-2021-45036

CVE.ORG link : CVE-2021-45036


JSON object : View

Products Affected

velneo

  • vclient
CWE
CWE-287

Improper Authentication

CWE-290

Authentication Bypass by Spoofing