Vulnerability Description
Single Connect does not perform an authorization check when using the "sc-diagnostic-ui" module. A remote attacker could exploit this vulnerability to access the device information page. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Krontech | Single Connect | < 2.16 |
Related Weaknesses (CWE)
References
- https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-22-0093
- https://www.usom.gov.tr/bildirim/tr-22-0093Third Party Advisory
- https://www.usom.gov.tr/bildirim/tr-22-0093Third Party Advisory
FAQ
What is CVE-2021-44794?
CVE-2021-44794 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Single Connect does not perform an authorization check when using the "sc-diagnostic-ui" module. A remote attacker could exploit this vulnerability to access the device information page. The exploitat...
How severe is CVE-2021-44794?
CVE-2021-44794 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44794?
Check the references section above for vendor advisories and patch information. Affected products include: Krontech Single Connect.