User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the CommandPost, these values could be decoded and used to login to the application. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.3. This vulnerability has been addressed in version 9.3.3 and subsequent versions.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Fidelis

Published: 2021-06-18T00:00:00

Updated: 2021-09-07T18:22:13

Reserved: 2021-06-18T00:00:00


Link: CVE-2021-35050

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-06-25T12:15:08.683

Modified: 2022-08-12T18:01:37.160


Link: CVE-2021-35050

JSON object: View

cve-icon Redhat Information

No data.