CVE-2021-32958 - CVE House
Back to Database
Status published Medium CVE-2021-32958

Claroty Secure Remote Access Site - Authentication Bypass Using an Alternate Path or Channel

Vulnerability Description

Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows an attacker with local command line interface access to gain the secret key, subsequently allowing them to generate valid session tokens for the web user interface (UI). With access to the web UI an attacker can access assets managed by the SRA installation and could compromise the installation.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-32958

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Alphastrike Labs reported this vulnerability to Claroty.

Affected Vendor

Affected Software

Secure Remote Access (SRA) Site
Vulnerable Versions:
versions 3.0 through 3.2

Timeline

Official Publish: May 23rd, 2022
Last Modified: April 16th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)