CVE-2021-36921
Summary
| CVE | CVE-2021-36921 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-12 18:15:00 UTC |
| Updated | 2021-08-24 15:56:00 UTC |
| Description | AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 has Improper Authentication. An attacker can gain administrative access by modifying the response to an authentication check request. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Monitorapp | Application Insight Manager | All | All | All | All |
| Application | Monitorapp | Application Insight Web Application Firewall | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability-Disclosures/FEYE-2021-0021.md at master · fireeye/Vulnerability-Disclosures · GitHub | MISC | github.com | |
| WAF | Web application firewall | Protect your site | AIWAF | MISC | www.monitorapp.com | |
| CVE 2021 36921 · monitorapp-aicc/report Wiki · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.