← back
CVE-2021-45036

Velneo vClient improper authentication

CVSS 8.7 HIGHEPSS 0.7%CWE-290
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.7EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
28 Nov 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Affected products
Velneo · Velneo vClient

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →