CVE-2021-32076
Last modified
CVE-2021-32076 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.. EPSS estimates a 1.17% chance of exploitation in the next 30 days.
Description
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Solarwinds | Web Help Desk | <= 12.7.2 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/208278Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-32076?
How severe is CVE-2021-32076?
How do I fix CVE-2021-32076?
Are you affected by CVE-2021-32076?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
