VulnerabilityModified
CVE-2021-27651
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.
CRITICAL 9.8EPSS 53.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 53.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 53.84% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- pega/infinity
- Source
- security@pega.com
References
- https://collaborate.pega.com/discussion/pega-security-advisory-a21-hotfix-matrixRelease Notes, Vendor Advisory
- https://collaborate.pega.com/discussion/pega-security-advisory-a21-hotfix-matrixRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.