← Volver a CVEs
CVE-2021-22860
CRITICAL9.8
Descripcion
EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote attacker to obtain users’ credential information without logging in the system, and further acquire the privileged permissions and execute arbitrary commends.
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado3/17/2021
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
eic:e-document_system
Debilidades (CWE)
CWE-287
Referencias
https://gist.github.com/tonykuo76/17d497b3472a80a5e8914227e81e6fa3(twcert@cert.org.tw)
https://www.chtsecurity.com/news/12929036-924b-4b89-8a0e-3e7155e19011(twcert@cert.org.tw)
https://www.twcert.org.tw/tw/cp-132-4518-c813c-1.html(twcert@cert.org.tw)
https://gist.github.com/tonykuo76/17d497b3472a80a5e8914227e81e6fa3(af854a3a-2127-422b-91ae-364da2661108)
https://www.chtsecurity.com/news/12929036-924b-4b89-8a0e-3e7155e19011(af854a3a-2127-422b-91ae-364da2661108)
https://www.twcert.org.tw/tw/cp-132-4518-c813c-1.html(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.