Record summary

CVE-2021-44152 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALReprise License Manager 14.2 - Authentication BypassCVSS 9.8

Reprise License Manager (RLM) 14.2 does not verify authentication or authorization and allows unauthenticated users to change the password of any existing user.

Impact

Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the Reprise License Manager.

Remediation

Apply the latest security patch or upgrade to a patched version of Reprise License Manager to mitigate this vulnerability.

WeaknessesCWE-306
AuthorsAkincibor
Template tagscvecve2021packetstormrlmauth-bypassreprisesoftwarevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:reprisesoftware:reprise_license_manager:*:*:*:*:*:*:*:*
Shodan: http.html:"Reprise License Manager"
Shodan: http.html:"reprise license"
Shodan: http.html:"reprise license manager"
FOFA: body="reprise license manager"
FOFA: body="reprise license"
Google: inurl:"/goforms/menu"

Source: ProjectDiscovery

References

4