CVE-2021-41320
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
15/10/2021
Last modified:
30/05/2025
Description
A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than the average authenticated user. NOTE: the vendor disputes this because the password is not hardcoded (it can be changed during installation or at any later time).
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:iongroup:wallstreet_suite:7.4.83:*:*:*:*:*:x64:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://cds.thalesgroup.com/en/tcs-cert/CVE-2021-41320
- https://client-connect.iongroup.com/library/content/treasury-management/wallstreet-suite/security/suite-7-4-83/user-passwords/
- https://excellium-services.com/cert-xlm-advisory/CVE-2021-41320
- https://iongroup.com/ion-treasury/products/wallstreet-suite/
- https://client-connect.iongroup.com/library/content/treasury-management/wallstreet-suite/security/suite-7-4-83/user-passwords/
- https://excellium-services.com/cert-xlm-advisory/CVE-2021-41320
- https://iongroup.com/ion-treasury/products/wallstreet-suite/