First published: Mon Apr 11 2022(Updated: )
Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this specific scenario, the application's network traffic was intercepted using a proxy server set up in 'transparent' mode while a certificate with an invalid hostname was active. The Android application was found to have hostname verification issues during the server setup and login flows; however, the application did not process requests post-login.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Verse | <12.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27768 is a vulnerability that allows for a Man-in-the-Middle (MITM) attack, indicating a lack of hostname verification.
CVE-2021-27768 works by intercepting network traffic using a proxy server set up in 'transparent' mode, allowing for sensitive account information to be intercepted.
The severity of CVE-2021-27768 is medium with a severity value of 5.9.
The Hcltech Verse application with a version up to and excluding 12.0.9 is affected by CVE-2021-27768.
To fix CVE-2021-27768, it is recommended to enable proper hostname verification in the application's network traffic.