🔙 목록으로 돌아가기

CVE-2021-27651: Pega Infinity - Authentication Bypass

TitlePega Infinity - Authentication Bypass
Authoridealphase,daffainfo
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the Pega Infinity application.
RemediationApply the necessary security patches or updates provided by Pega Infinity to mitigate the authentication bypass vulnerability (CVE-2021-27651).
CVSS Score9.8
EPSS Score0.92177
CVE IDCVE-2021-27651
CWE IDCWE-287
Tags cve2021 cve pega auth-bypass passive vuln

🔍 Vulnerability Description

Pega Infinity versions 8.2.1 through 8.5.2 contain an authentication bypass vulnerability because the password reset functionality for local accounts can be used to bypass local authentication checks.

🌐 HTTP Request

GET /prweb/PRAuth/app/default/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (SS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-27651.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-27651.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A