CVE-2021-26909

LOW

Automox Agent < 31 - Unauthenticated Sensitive Information Exposure via S3 Bucket Endpoint

Title source: llm
STIX 2.1

Description

Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which could be brute-forced by an attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent.

Scores

CVSS v3 3.7
EPSS 0.0073
EPSS Percentile 49.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-284 CWE-330
Status published
Products (1)
automox/automox < 31
Published Apr 23, 2021
Tracked Since Feb 18, 2026