StarWind SAN & NAS build 1578 and StarWind Command Center Build 6864 Update Manager allows authentication with JTW token which is signed with any key. An attacker could use self-signed JTW token to bypass authentication resulting in escalation of privileges.
References
| Link | Resource |
|---|---|
| https://www.starwindsoftware.com/security/sw-20211512-0001/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-01-04 16:15
Updated : 2022-07-12 17:42
NVD link : CVE-2021-45389
Mitre link : CVE-2021-45389
JSON object : View
Products Affected
starwind
- command_center
- san\&nas
CWE
CWE-287
Improper Authentication
