« Volver al listado

CVE-2021-45036

Estado: ModificadaAlta (7.4)—

Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-45036",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2021-45036",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-25T14:59:33.236304Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@incibe.es",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.4,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@incibe.es",
      "affectedData": [
        {
          "vendor": "Velneo",
          "product": "Velneo vClient",
          "versions": [
            {
              "status": "affected",
              "version": "28.1.3"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2022-11-28T16:15:09.090",
  "references": [
    {
      "url": "https://doc.velneo.com/v/32/velneo-vserver/funcionalidades/protocolo-vatps",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve-coordination@incibe.es"
    },
    {
      "url": "https://doc.velneo.com/v/32/velneo/funcionalidades-comunes/conexion-con-velneo-vserver",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve-coordination@incibe.es"
    },
    {
      "url": "https://doc.velneo.com/v/32/velneo/notas-de-la-version#a-partir-de-esta-version-todos-los-servidores-arrancaran-con-protocolo-vatps",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve-coordination@incibe.es"
    },
    {
      "url": "https://doc.velneo.com/v/32/velneo/notas-de-la-version#mejoras-de-seguridad-en-validacion-de-usuario-y-contrasena",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve-coordination@incibe.es"
    },
    {
      "url": "https://velneo.es/mivelneo/listado-de-cambios-velneo-32/",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve-coordination@incibe.es"
    },
    {
      "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/velneo-vclient-improper-authentication-0",
      "source": "cve-coordination@incibe.es"
    },
    {
      "url": "https://www.velneo.com/blog/disponible-la-nueva-version-velneo-32",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve-coordination@incibe.es"
    },
    {
      "url": "https://doc.velneo.com/v/32/velneo-vserver/funcionalidades/protocolo-vatps",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://doc.velneo.com/v/32/velneo/funcionalidades-comunes/conexion-con-velneo-vserver",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://doc.velneo.com/v/32/velneo/notas-de-la-version#a-partir-de-esta-version-todos-los-servidores-arrancaran-con-protocolo-vatps",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://doc.velneo.com/v/32/velneo/notas-de-la-version#mejoras-de-seguridad-en-validacion-de-usuario-y-contrasena",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://velneo.es/mivelneo/listado-de-cambios-velneo-32/",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/velneo-vclient-improper-authentication-0",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.velneo.com/blog/disponible-la-nueva-version-velneo-32",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@incibe.es",
      "description": [
        {
          "lang": "en",
          "value": "CWE-290"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server."
    },
    {
      "lang": "es",
      "value": "Velneo vClient en su versión 28.1.3 podría permitir que un atacante con conocimiento del nombre de usuario y la contraseña hash de la víctima falsifique la identificación de la víctima en el servidor."
    }
  ],
  "lastModified": "2026-06-17T04:13:04.687",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:velneo:vclient:28.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2802675E-9543-403C-95FF-3CFF1FC01896"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@incibe.es"
}