Velneo vClient improper authentication
Vulnerability Description
Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-45036
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Jesús Ródenas Huerta, @Marmeus
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/velneo-vclient-improper-authentication-0
- https://www.velneo.com/blog/disponible-la-nueva-version-velneo-32
- https://doc.velneo.com/v/32/velneo/notas-de-la-version#mejoras-de-seguridad-en-validacion-de-usuario-y-contrasena
- https://velneo.es/mivelneo/listado-de-cambios-velneo-32/
- https://doc.velneo.com/v/32/velneo/notas-de-la-version#a-partir-de-esta-version-todos-los-servidores-arrancaran-con-protocolo-vatps
- https://doc.velneo.com/v/32/velneo-vserver/funcionalidades/protocolo-vatps
- https://doc.velneo.com/v/32/velneo/funcionalidades-comunes/conexion-con-velneo-vserver
Affected Vendor
Velneo
View all reports →