CVE-2021-40067
MEDIUMNetmotionsoftware Mobility < 12.14 - Incorrect Permission Assignment
Title source: ruleDescription
The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v12.14.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.netmotionsoftware.com/security-advisories/cve-2021-40067
Scores
CVSS v3
6.8
EPSS
0.0016
EPSS Percentile
36.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-732
Status
published
Products (1)
netmotionsoftware/mobility
< 12.14
Published
Sep 16, 2021
Tracked Since
Feb 18, 2026