CVE-2021-26909

LOW

Automox < 31 - Improper Access Control

Title source: rule
STIX 2.1

Description

Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which could be brute-forced by an attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent.

Scores

CVSS v3 3.7
EPSS 0.0020
EPSS Percentile 42.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-284 CWE-330
Status published
Products (1)
automox/automox < 31
Published Apr 23, 2021
Tracked Since Feb 18, 2026