SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-30357

SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access.

MEDIUM 5.3EPSS 22.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 22.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
22.79% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-209
Affected
checkpoint/ssl network extender
Source
cve@checkpoint.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.