Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature. The lack of correct configuration leads to recovery of the password reset link generated via the password reset functionality, and thus an unauthenticated attacker can set an arbitrary password for any user.
References
Link | Resource |
---|---|
https://0xdb9.in/2021/06/07/cve-2021-28293.html | Exploit Third Party Advisory |
https://www.seceon.com/advanced-siem-aisiem | Product Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-06-08T18:00:47
Updated: 2021-07-12T11:52:25
Reserved: 2021-03-12T00:00:00
Link: CVE-2021-28293
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-06-08T18:15:08.277
Modified: 2022-04-19T03:44:11.683
Link: CVE-2021-28293
JSON object: View
Redhat Information
No data.
CWE