CVE-2021-33895
ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running BBSV to login to the Backbox UI application, the system procedure (USER_AUTHENTICATE_) used for verifying the Password returns 0 (no error). The reason is that the user is not running the XYGate application. Hence, BBSV assumes the Password is correct. For H4.09, the affected version isT0954V04^AAO. For E4.09, the affected version is 22SEP2020. Note: If your current version is E4.10-16MAY2021 (version procedure T9999V04_16MAY2022_BPAKETI_10), a hotfix (FIXPAK-19OCT-2022) is available in version E4.10-19OCT2022. Resolution to CVE-2021-33895 in version E4.11-19OCT2022
Published:Jun 25, 2021
Last Modified:Nov 21, 2024
EPS:Jun 25, 2021
EPSS Score:0.00386
CVSS Score:8.1
Affected Products
Vendor
Product
Action
Vendor
Etinet
Product
Backbox E4.09
Etinet
Backbox E4.09
Vendor
Etinet
Product
Backbox E4.09 Firmware
Etinet
Backbox E4.09 Firmware
Vendor
Hpe
Product
Backbox H4.09
Hpe
Backbox H4.09
Vendor
Hpe
Product
Backbox H4.09 Firmware
Hpe
Backbox H4.09 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
