{"api_version":"1","generated_at":"2026-07-24T17:48:32+00:00","cve":"CVE-2021-36921","urls":{"html":"https://cve.report/CVE-2021-36921","api":"https://cve.report/api/cve/CVE-2021-36921.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-36921","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-36921"},"summary":{"title":"CVE-2021-36921","description":"AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 has Improper Authentication. An attacker can gain administrative access by modifying the response to an authentication check request.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-08-12 18:15:00","updated_at":"2021-08-24 15:56:00"},"problem_types":["CWE-287"],"metrics":[],"references":[{"url":"https://github.com/fireeye/Vulnerability-Disclosures/blob/master/FEYE-2021-0021/FEYE-2021-0021.md","name":"https://github.com/fireeye/Vulnerability-Disclosures/blob/master/FEYE-2021-0021/FEYE-2021-0021.md","refsource":"MISC","tags":[],"title":"Vulnerability-Disclosures/FEYE-2021-0021.md at master · fireeye/Vulnerability-Disclosures · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.monitorapp.com/waf/","name":"https://www.monitorapp.com/waf/","refsource":"MISC","tags":[],"title":"WAF | Web application firewall | Protect your site | AIWAF","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/monitorapp-aicc/report/wiki/CVE-2021-36921","name":"https://github.com/monitorapp-aicc/report/wiki/CVE-2021-36921","refsource":"CONFIRM","tags":[],"title":"CVE 2021 36921 · monitorapp-aicc/report Wiki · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-36921","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-36921","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"36921","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"monitorapp","cpe5":"application_insight_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"36921","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"monitorapp","cpe5":"application_insight_web_application_firewall","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-36921","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 has Improper Authentication. An attacker can gain administrative access by modifying the response to an authentication check request."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.monitorapp.com/waf/","refsource":"MISC","name":"https://www.monitorapp.com/waf/"},{"refsource":"MISC","name":"https://github.com/fireeye/Vulnerability-Disclosures/blob/master/FEYE-2021-0021/FEYE-2021-0021.md","url":"https://github.com/fireeye/Vulnerability-Disclosures/blob/master/FEYE-2021-0021/FEYE-2021-0021.md"},{"refsource":"CONFIRM","name":"https://github.com/monitorapp-aicc/report/wiki/CVE-2021-36921","url":"https://github.com/monitorapp-aicc/report/wiki/CVE-2021-36921"}]}},"nvd":{"publishedDate":"2021-08-12 18:15:00","lastModifiedDate":"2021-08-24 15:56:00","problem_types":["CWE-287"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:monitorapp:application_insight_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"b107","versionEndExcluding":"b115","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:a:monitorapp:application_insight_web_application_firewall:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"36921","Ordinal":"212491","Title":"CVE-2021-36921","CVE":"CVE-2021-36921","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"36921","Ordinal":"1","NoteData":"AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 has Improper Authentication. An attacker can gain administrative access by modifying the response to an authentication check request.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"36921","Ordinal":"2","NoteData":"2021-08-12","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"36921","Ordinal":"3","NoteData":"2021-08-12","Type":"Other","Title":"Modified"}]}}}