CVE-2021-38459

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/10/2021
Last modified:
27/10/2021

Description

The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specific .exe is not restarted often, it is possible to access the needed handshake packets between admin/client connections. Using the SYSDBA permission, an attacker can change user passwords or delete the database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:auvesy:versiondog:*:*:*:*:*:*:*:* 8.0.0 (excluding)


References to Advisories, Solutions, and Tools