ZeroHour

CVE-2021-27651

CVSS 3.1
9.8 critical
EPSS
54%p99
Published
()
Modified
Description

In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.

Vendors
pega
Products
infinity
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.