CVE-2021-45389

StarWind SAN & NAS build 1578 and StarWind Command Center Build 6864 Update Manager allows authentication with JTW token which is signed with any key. An attacker could use self-signed JTW token to bypass authentication resulting in escalation of privileges.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:starwind:command_center:6864:*:*:*:*:*:*:*
cpe:2.3:a:starwind:san\&nas:1578:*:*:*:*:*:*:*

Information

Published : 2022-01-04 16:15

Updated : 2022-07-12 17:42


NVD link : CVE-2021-45389

Mitre link : CVE-2021-45389


JSON object : View

Products Affected

starwind

  • command_center
  • san\&nas
CWE
CWE-287

Improper Authentication