CVE-2021-32504: Medium severity sick ftmc firmware vulnerability
Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32504?
CVE-2021-32504 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2021-32504?
To fix CVE-2021-32504, ensure that sensitive web URLs are restricted to authenticated maintenance users only.
Who is affected by CVE-2021-32504?
CVE-2021-32504 affects Sick FTMG firmware versions prior to 2.8.
What types of attacks can be launched due to CVE-2021-32504?
An attacker could exploit CVE-2021-32504 to gain unauthorized access to sensitive information, potentially leading to further system attacks.
Is there a patch available for CVE-2021-32504?
Yes, users should upgrade to Sick FTMG firmware version 2.8 or later to mitigate CVE-2021-32504.