9.8
CVSSv3

CVE-2021-35048

Published: 25/06/2021 Updated: 14/09/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis software. The vulnerability is present in Fidelis Network and Deception versions before 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fidelissecurity deception

fidelissecurity deception 9.4

fidelissecurity network

fidelissecurity network 9.4