Skip to content
COOEY

EXPOSURES › CVE-2021-41716

CVE-2021-41716

CRITICAL
DETAIL
SourceNVD · cve Published2021-12-07 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-41716 ↗
SHAME 35/100

Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
CVE-2021-41716 represents a critical remote account takeover vulnerability in a government-issued application, indicating severe security mismanagement and potential regulatory fallout for the vendor.
cooey ↗ severe-fallout -0.90
Critical vulnerability disclosure
"Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function"
app.opencve.io ↗ severe-fallout +0.00
Neutral database listing
www.cvefind.com ↗ severe-fallout +0.00
Neutral database listing
www.usatoday.com ↗ severe-fallout +0.00
Irrelevant content
SentinelOne ↗ severe-fallout +0.00
Irrelevant content
cvefeed.io ↗ severe-fallout +0.00
Irrelevant content
www.europesays.com ↗ severe-fallout +0.00
Irrelevant content
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.