CVE-2021-28293
Summary
| CVE | CVE-2021-28293 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-08 18:15:00 UTC |
| Updated | 2022-04-19 03:44:00 UTC |
| Description | Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature. The lack of correct configuration leads to recovery of the password reset link generated via the password reset functionality, and thus an unauthenticated attacker can set an arbitrary password for any user. |
Risk And Classification
Problem Types: CWE-640
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Coming Soon | MISC | aisiem.com | |
| CVE-2021-28293 | Saraunsh0x9 | MISC | 0xdb9.in | |
| Advanced SIEM [aiSIEM] - Seceon | MISC | www.seceon.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.