MDT AutoSave Generation of Error Message Containing Sensitive Information
Vulnerability Description
An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working directory where the read and write activity can be initiated.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-32937
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Amir Preminger of Claroty Research reported these vulnerabilities to MDT Software.
More from MDT Software
View All →Affected Vendor
MDT Software
View all reports →