EXPOSURES › CVE-2021-41716
CVE-2021-41716
CRITICAL
DETAIL
SourceNVD · cve
Published2021-12-07
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-41716 ↗
SHAME 35/100
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.80
CVE-2021-41716 represents a critical remote account takeover vulnerability in a government-issued application, indicating severe security mismanagement and potential regulatory fallout for the vendor.
Critical vulnerability disclosure
"Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function"
Neutral database listing
Neutral database listing
Irrelevant content
Irrelevant content
Irrelevant content
Irrelevant content
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.