CVE-2021-32958
MEDIUMClaroty Secure Remote Access Site <3.2 - Privilege Escalation
Title source: llmDescription
Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows an attacker with local command line interface access to gain the secret key, subsequently allowing them to generate valid session tokens for the web user interface (UI). With access to the web UI an attacker can access assets managed by the SRA installation and could compromise the installation.
References (1)
Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-21-180-06
Scores
CVSS v3
5.5
EPSS
0.0022
EPSS Percentile
11.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-288
Status
published
Products (1)
claroty/secure_remote_access
3.0 - 3.2
Published
May 23, 2022
Tracked Since
Feb 18, 2026