CVE-2021-45036

Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server.
References
Link Resource
https://doc.velneo.com/v/32/velneo-vserver/funcionalidades/protocolo-vatps Vendor Advisory
https://doc.velneo.com/v/32/velneo/funcionalidades-comunes/conexion-con-velneo-vserver Vendor Advisory
https://doc.velneo.com/v/32/velneo/notas-de-la-version#a-partir-de-esta-version-todos-los-servidores-arrancaran-con-protocolo-vatps Vendor Advisory
https://doc.velneo.com/v/32/velneo/notas-de-la-version#mejoras-de-seguridad-en-validacion-de-usuario-y-contrasena Release Notes Vendor Advisory
https://velneo.es/mivelneo/listado-de-cambios-velneo-32/ Release Notes Vendor Advisory
https://www.incibe.es/en/incibe-cert/notices/aviso/velneo-vclient-improper-authentication-0
https://www.velneo.com/blog/disponible-la-nueva-version-velneo-32 Release Notes Vendor Advisory
https://doc.velneo.com/v/32/velneo-vserver/funcionalidades/protocolo-vatps Vendor Advisory
https://doc.velneo.com/v/32/velneo/funcionalidades-comunes/conexion-con-velneo-vserver Vendor Advisory
https://doc.velneo.com/v/32/velneo/notas-de-la-version#a-partir-de-esta-version-todos-los-servidores-arrancaran-con-protocolo-vatps Vendor Advisory
https://doc.velneo.com/v/32/velneo/notas-de-la-version#mejoras-de-seguridad-en-validacion-de-usuario-y-contrasena Release Notes Vendor Advisory
https://velneo.es/mivelneo/listado-de-cambios-velneo-32/ Release Notes Vendor Advisory
https://www.incibe.es/en/incibe-cert/notices/aviso/velneo-vclient-improper-authentication-0
https://www.velneo.com/blog/disponible-la-nueva-version-velneo-32 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:velneo:vclient:28.1.3:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-11-28 16:15

Updated : 2024-11-21 06:31


NVD link : CVE-2021-45036

Mitre link : CVE-2021-45036

CVE.ORG link : CVE-2021-45036


JSON object : View

Products Affected

velneo

  • vclient
CWE
CWE-290

Authentication Bypass by Spoofing

CWE-287

Improper Authentication