CVE-2021-25923
Estado: ModificadaAlta (8.1)—
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.34%
- Percentil entre todas las CVEs puntuadas: 70
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-521
Referencias
- https://github.com/openemr/openemr/commit/28ca5c008d4a408b60001a67dfd3e0915f9181e0
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25923
- https://github.com/openemr/openemr/commit/28ca5c008d4a408b60001a67dfd3e0915f9181e0
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25923
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-25923",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "vulnerabilitylab@mend.io",
"affectedData": [
{
"vendor": "n/a",
"product": "openemr",
"versions": [
{
"status": "affected",
"version": "v5.0.0, v5.0.0.5, v5.0.0.6, v5.0.1, v5.0.1.1, v5.0.1.2, v5.0.1.3, v5.0.1.4, v5.0.1.5, v5.0.1.6, v5.0.1.7, v5.0.2, v5.0.2.1, v5.0.2.2, v5.0.2.3, v5.0.2.4, v6.0.0, v6.0.0.1"
}
]
}
]
}
],
"published": "2021-06-24T11:15:07.877",
"references": [
{
"url": "https://github.com/openemr/openemr/commit/28ca5c008d4a408b60001a67dfd3e0915f9181e0",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "vulnerabilitylab@mend.io"
},
{
"url": "https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25923",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "vulnerabilitylab@mend.io"
},
{
"url": "https://github.com/openemr/openemr/commit/28ca5c008d4a408b60001a67dfd3e0915f9181e0",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25923",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-521"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover."
},
{
"lang": "es",
"value": "En OpenEMR, versiones 5.0.0 hasta 6.0.0.1, son vulnerables a requisitos de contraseñas débiles, ya que no aplica un límite de longitud máxima de la contraseña. Si un usuario malicioso esta consciente los primeros 72 caracteres de la contraseña del usuario víctima, puede aprovecharlos para hacerse con una cuenta"
}
],
"lastModified": "2026-06-17T03:42:35.463",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58E731FF-CAE5-470F-91F3-B8B749DD273D",
"versionEndIncluding": "6.0.0.1",
"versionStartIncluding": "5.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vulnerabilitylab@mend.io"
}