CVE-2021-32951: Advantech WebAccess/NMS Improper Authentication
Published Oct 27, 2021
·Updated
WebAccess/NMS (Versions prior to v3.0.3Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources monitored and controlled by the WebAccess/NMS, as well as IP addresses and names of all the devices managed via WebAccess/NMS.
Affected Software
2 affected components
Advantech Webaccess\/nms<=3.0.3
Advantech WebAccess/NMS: Versions prior to v3.0.3_Build6299
Remediation
Patch Available
Information
Advantech recommends updating to Version 3.0.3
Event History
Oct 27, 2021
CVE Published
via MITRE·12:54 AM
Data Sourced
via MITRE·12:54 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-32951?
CVE-2021-32951 has a medium severity level due to its improper authentication vulnerability.
2
How do I fix CVE-2021-32951?
To fix CVE-2021-32951, upgrade the WebAccess/NMS to version 3.0.3_Build6299 or later.
3
What are the impacts of CVE-2021-32951?
CVE-2021-32951 may allow unauthorized users to access monitored resources and device details.
4
Which versions of WebAccess/NMS are affected by CVE-2021-32951?
WebAccess/NMS versions prior to v3.0.3_Build6299 are affected by CVE-2021-32951.
5
Is there a workaround for CVE-2021-32951?
Currently, applying the recommended upgrade is the best way to mitigate the risks from CVE-2021-32951.