CVE ID | |
CVSS SCORE | 9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
AFFECTED VENDORS |
Vinchin |
AFFECTED PRODUCTS |
Backup and Recovery |
VULNERABILITY DETAILS |
This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of API access tokens. The issue results from the use of a hard-coded cryptographic key to validate the access token. An attacker can leverage this vulnerability to bypass authentication on the system. |
ADDITIONAL DETAILS |
This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 120 day deadline. 08/04/21 – ZDI requested PSIRT contact -- Mitigation: |
DISCLOSURE TIMELINE |
|
CREDIT | Esjay |