Vulnerability Description
EMQ X Dashboard V3.0.0 is affected by username enumeration in the "/api /v3/auth" interface. When a user login, the application returns different results depending on whether the account is correct, that allowed an attacker to determine if a given username was valid
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Emqx | Emqx | 3.0.0 |
References
- https://github.com/emqx/emqx/issues/6791ExploitIssue TrackingThird Party Advisory
- https://github.com/emqx/emqx/issues/6791ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2021-46434?
CVE-2021-46434 is a vulnerability with a CVSS score of 5.3 (MEDIUM). EMQ X Dashboard V3.0.0 is affected by username enumeration in the "/api /v3/auth" interface. When a user login, the application returns different results depending on whether the account is correct, t...
How severe is CVE-2021-46434?
CVE-2021-46434 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-46434?
Check the references section above for vendor advisories and patch information. Affected products include: Emqx Emqx.