CVE-2021-32003
Last modified
CVE-2021-32003 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Secomea | Sitemanager Firmware | < 9.5.621256022 |
References
- https://www.secomea.com/support/cybersecurity-advisoryVendor Advisory
- https://www.secomea.com/support/cybersecurity-advisoryVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-32003?
How severe is CVE-2021-32003?
How do I fix CVE-2021-32003?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-31998A Incorrect Default Permissions vulnerability in the packagi…7.8
- CVE-2021-31999A Reliance on Untrusted Inputs in a Security Decision vulner…8.8
- CVE-2021-3200Buffer overflow vulnerability in libsolv 2020-12-13 via the …3.3
- CVE-2021-32000A UNIX Symbolic Link (Symlink) Following vulnerability in th…7.1
- CVE-2021-32001K3s in SUSE Rancher allows any user with direct access to th…6.5
- CVE-2021-32002Improper Access Control vulnerability in web service of Seco…3.3
- CVE-2021-32004This issue affects: Secomea GateManager All versions prior t…5.3
- CVE-2021-32005Cross-site Scripting (XSS) vulnerability in log view of Seco…5.4
- CVE-2021-32006This issue affects: Secomea GateManager Version 9.6.62142101…4.3
- CVE-2021-32007This issue affects: Secomea GateManager Version 9.5 and all …3.5
- CVE-2021-32008This issue affects: Secomea GateManager Version 9.6.62142101…8.7
- CVE-2021-32009Cross-site Scripting (XSS) vulnerability in firmware section…6.1
Are you affected by CVE-2021-32003?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
