Skip to content
COOEY

EXPOSURES › CVE-2021-32648

CVE-2021-32648

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-32648 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatchedauth-bypass

October CMS improper authentication flaw allowed attackers to bypass password reset and gain account access via crafted requests.

October CMS versions with the improper authentication flaw in the october/system package allowed attackers to request a password reset and then use a specially crafted request to gain unauthorized account access. DIB organizations must ensure their CMS platforms are patched to prevent account takeover and data breaches. This failure highlights the risk of relying on unpatched software with known authentication bypasses.

Shame score — A known authentication bypass in a widely used CMS that was actively exploited in the wild, indicating negligent patching and avoidable account compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.