CVE-2021-45036

HIGH

Velneo vClient 28.1.3 - Authentication Bypass by Spoofing via Hashed Password

Title source: llm
STIX 2.1

Description

Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server.

Scores

CVSS v3 8.7
EPSS 0.0070
EPSS Percentile 49.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287 CWE-290
Status published
Products (1)
velneo/vclient 28.1.3
Published Nov 28, 2022
Tracked Since Feb 18, 2026