SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-32543

After login, remote attackers can manipulate cookies to access other accounts and trade in the stock market with spoofed identity.

MEDIUM 5.4EPSS 0.76%

Does this matter?

Lower severity and a low EPSS score (0.76%). Track it; it rarely justifies an emergency change on its own.

Description

The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote attackers can manipulate cookies to access other accounts and trade in the stock market with spoofed identity.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS
0.76% probability · 53th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
sysjust/cts web
Source
twcert@cert.org.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.