CVE-2021-3833: Integria IMS incorrect authorization
Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit this vulnerability in order to login in the system with different passwords.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Integria IMSto a version that resolves this vulnerability.Fixed in 5.0 93
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-3833.
What is the title of this vulnerability?
The title of this vulnerability is Integria IMS incorrect authorization.
What is the severity of CVE-2021-3833?
The severity of CVE-2021-3833 is critical with a severity value of 9.8.
How does the vulnerability CVE-2021-3833 impact Integria IMS?
The vulnerability CVE-2021-3833 allows an attacker with a specific formatted password to exploit the loose comparator used for password validation and log in to the system with different passwords.
How can I fix the vulnerability CVE-2021-3833 in Integria IMS 5.0.92?
To fix the vulnerability CVE-2021-3833 in Integria IMS 5.0.92, you should update to a patched version provided by Artica Integria IMS.