CVE-2021-27651: Critical severity pega infinity vulnerability
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27651?
CVE-2021-27651 is a vulnerability found in versions 8.2.1 through 8.5.2 of Pega Infinity where the password reset functionality for local accounts can be used to bypass local authentication checks.
What is the severity of CVE-2021-27651?
The severity of CVE-2021-27651 is critical with a CVSS score of 9.8.
How does CVE-2021-27651 affect Pega Infinity?
CVE-2021-27651 affects Pega Infinity versions 8.2.1 through 8.5.2, allowing for bypass of local authentication checks through the password reset functionality for local accounts.
Is there a fix available for CVE-2021-27651?
Yes, a hotfix is available for CVE-2021-27651. Please refer to the Pega Security Advisory A21 Hotfix Matrix for more information.
Where can I find more information about CVE-2021-27651?
You can find more information about CVE-2021-27651 in the Pega Security Advisory A21 Hotfix Matrix.