CVE-2021-45810
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/03/2022
Last modified:
05/03/2024
Description
GlobalProtect-openconnect versions prior to 2.0.0 (exclusive) are affected by incorrect access control in GPService through DBUS, GUI. The way GlobalProtect-Openconnect is set up enables arbitrary users to start a VPN connection to arbitrary servers. By hosting an openconnect compatible server, the attack can redirect the entire host's traffic via their own server.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:globalprotect-openconnect_project:globalprotect-openconnect:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



