ZeroHour

CVE-2021-45389

CVSS 3.1
9.8 critical
EPSS
1%p65
Published
()
Modified
Description

A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This affects StarWind SAN and NAS build 1578 and StarWind Command Center build 6864.

Vendors
starwind
Products
command center, san\&nas
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.