Vulnerability Description
The CTS Web transaction system related to authentication and session management is implemented incorrectly, which allows remote unauthenticated attackers can send a large number of valid usernames, and force those logged-in account to log out, causing the user to be unable to access the services
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sysjust | Cts Web | < 2021.3.24 |
Related Weaknesses (CWE)
References
- https://www.chtsecurity.com/news/40e165e2-e539-49bc-bcf1-e3b27c29e344Third Party Advisory
- https://www.twcert.org.tw/tw/cp-132-4757-893eb-1.htmlThird Party Advisory
- https://www.chtsecurity.com/news/40e165e2-e539-49bc-bcf1-e3b27c29e344Third Party Advisory
- https://www.twcert.org.tw/tw/cp-132-4757-893eb-1.htmlThird Party Advisory
FAQ
What is CVE-2021-32541?
CVE-2021-32541 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The CTS Web transaction system related to authentication and session management is implemented incorrectly, which allows remote unauthenticated attackers can send a large number of valid usernames, an...
How severe is CVE-2021-32541?
CVE-2021-32541 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-32541?
Check the references section above for vendor advisories and patch information. Affected products include: Sysjust Cts Web.