PT-2021-20814 · Fidelis · Fidelis Network/Deception

·

CVE-2021-35050

·

Published

2021-06-25

·

Updated

2022-08-12

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Fidelis Network and Deception versions prior to 9.3.3
Description: The issue concerns user credentials being stored in a recoverable format within the system. If an attacker gains access to the CommandPost, they could decode and use these credentials to login to the application.
Recommendations: For versions prior to 9.3.3, update to version 9.3.3 or a subsequent version to resolve the issue. As a temporary workaround, consider restricting access to the CommandPost to minimize the risk of exploitation.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-35050

Affected Products

Fidelis Network/Deception