{"api_version":"1","generated_at":"2026-07-24T17:45:07+00:00","cve":"CVE-2021-42338","urls":{"html":"https://cve.report/CVE-2021-42338","api":"https://cve.report/api/cve/CVE-2021-42338.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-42338","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-42338"},"summary":{"title":"CVE-2021-42338","description":"4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt services by upload and execution of arbitrary files.","state":"PUBLIC","assigner":"cve@cert.org.tw","published_at":"2021-11-19 09:15:00","updated_at":"2022-08-09 14:40:00"},"problem_types":["CWE-287"],"metrics":[],"references":[{"url":"https://www.twcert.org.tw/tw/cp-132-5313-45bde-1.html","name":"N/A","refsource":"CONFIRM","tags":[],"title":"TWCERT/CC台灣電腦網路危機處理暨協調中心-4MOSAn GCB Doctor - Improper Authorization","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-42338","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-42338","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"42338","vulnerable":"1","versionEndIncluding":"20210708","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"4mosan","cpe5":"gcb_doctor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"AKA":"TWCERT/CC","ASSIGNER":"cve@cert.org.tw","DATE_PUBLIC":"2021-11-19T08:09:00.000Z","ID":"CVE-2021-42338","STATE":"PUBLIC","TITLE":"4MOSAn GCB Doctor - Improper Authorization"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"GCB Doctor","version":{"version_data":[{"version_affected":"<=","version_value":"20210708(v2.0)"}]}}]},"vendor_name":"4MOSAn"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt services by upload and execution of arbitrary files."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-285 Improper Authorization"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://www.twcert.org.tw/tw/cp-132-5313-45bde-1.html","name":"https://www.twcert.org.tw/tw/cp-132-5313-45bde-1.html"}]},"solution":[{"lang":"eng","value":"Update 4MOSAn GCB Doctor version to 20210811 (v2.0)"}],"source":{"advisory":"TVN-202111002","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2021-11-19 09:15:00","lastModifiedDate":"2022-08-09 14:40:00","problem_types":["CWE-287"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:4mosan:gcb_doctor:*:*:*:*:*:*:*:*","versionEndIncluding":"20210708","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"42338","Ordinal":"218303","Title":"CVE-2021-42338","CVE":"CVE-2021-42338","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"42338","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}