CVE-2021-21982

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
01/04/2021
Last modified:
06/04/2021

Description

VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token. Successful exploitation of this issue would result in the attacker being able to view and alter administrative configuration settings.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:carbon_black_cloud_workload:*:*:*:*:*:*:*:* 1.0.1 (including)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools