CVE-2021-44793
Last modified
CVE-2021-44793 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to access the device configuration page and export the data to an external file. EPSS estimates a 1.37% chance of exploitation in the next 30 days.
Description
Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to access the device configuration page and export the data to an external file. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information including the database credentials. Since the database runs with high privileges it is possible to execute commands with the attained credentials.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Krontech | Single Connect | < 2.16 |
References
- https://www.usom.gov.tr/bildirim/tr-22-0093Third Party Advisory
- https://www.usom.gov.tr/bildirim/tr-22-0093Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-44793?
How severe is CVE-2021-44793?
How do I fix CVE-2021-44793?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-44788Rejected reason: Not used
- CVE-2021-44789Rejected reason: Not used
- CVE-2021-4479Dräger Atlan A350 versions 1.00 up to and including 1.01 con…6.3
- CVE-2021-44790A carefully crafted request body can cause a buffer overflow…9.8
- CVE-2021-44791In Apache Druid 0.22.1 and earlier, certain specially-crafte…6.1
- CVE-2021-44792Single Connect does not perform an authorization check when …5.3
- CVE-2021-44794Single Connect does not perform an authorization check when …5.3
- CVE-2021-44795Single Connect does not perform an authorization check when …5.3
- CVE-2021-4480Dräger Protector Software prior to version 6.4.2 contains a …8.3
- CVE-2021-4481Dräger Protector Software prior to version 6.4.2 contains a …8.3
- CVE-2021-4482Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2021-44827There is remote authenticated OS command injection on TP-Lin…8.8
Are you affected by CVE-2021-44793?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
