CVE-2021-42810CWE-336

Safenet Authentication Service Remote Desktop Gateway prior to 2.0.3 may allow privilege escilation to authenticated users

High · published January 19, 2022

CVSS v3.1
7.8
EPSS
0%
Percentile
24.1
In the wild
Unconfirmed
What it is

A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00315 · 24.1th percentile
Weakness
CWE-336 · Same Seed in Pseudo-Random Number Generator (PRNG)
Published
2022-01-19T17:12Z
EPSS history
Timeline
  • 19 JAN 17:12Z
    Safenet Authentication Service Remote Desktop Gateway prior to 2.0.3 may allow privilege escilation to authenticated users
    cvelistv5