CVE-2021-22515

MEDIUM

NetIQ Advanced Authentication <6.3 SP4 Patch 1 - Auth Bypass

Title source: llm
STIX 2.1

Description

Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1.

Scores

CVSS v3 4.8
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-863
Status published
Products (2)
microfocus/netiq_advanced_authentication 6.3 (5 CPE variants)
microfocus/netiq_advanced_authentication < 6.3
Published Jul 12, 2021
Tracked Since Feb 18, 2026