Description
Pega Infinity versions 8.2.1 through 8.5.2 contain an authentication bypass vulnerability because the password reset functionality for local accounts can be used to bypass local authentication checks.
Pega Infinity versions 8.2.1 through 8.5.2 contain an authentication bypass vulnerability because the password reset functionality for local accounts can be used to bypass local authentication checks.
id: CVE-2021-27651
info:
name: Pega Infinity - Authentication Bypass
author: idealphase,daffainfo
severity: critical
description: Pega Infinity versions 8.2.1 through 8.5.2 contain an authentication bypass vulnerability because the password reset functionality for local accounts can be used to bypass local authentication checks.
impact: |
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the Pega Infinity application.
remediation: |
Apply the necessary security patches or updates provided by Pega Infinity to mitigate the authentication bypass vulnerability (CVE-2021-27651).
reference:
- https://github.com/samwcyo/CVE-2021-27651-PoC/blob/main/RCE.md
- https://nvd.nist.gov/vuln/detail/CVE-2021-27651
- https://collaborate.pega.com/discussion/pega-security-advisory-a21-hotfix-matrix
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/orangmuda/CVE-2021-27651
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2021-27651
cwe-id: CWE-287
epss-score: 0.53841
epss-percentile: 0.98944
cpe: cpe:2.3:a:pega:infinity:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: pega
product: infinity
tags: cve2021,cve,pega,auth-bypass,passive,vuln
http:
- method: GET
path:
- "{{BaseURL}}/prweb/PRAuth/app/default/"
host-redirects: true
max-redirects: 2
matchers-condition: and
matchers:
- type: dsl
dsl:
- compare_versions(version, '< 8.5.2', '>= 8.2.1')
- type: word
part: body
words:
- 'Pega Infinity'
- type: status
status:
- 200
extractors:
- type: regex
name: version
group: 1
regex:
- '(?m)<span>Pega ([0-9.]+)</span>'
internal: true
- type: regex
group: 1
regex:
- '(?m)<span>Pega ([0-9.]+)</span>'
# digest: 490a00463044022074af8b4bc187065d0bdece34ed2c2558320b48c23e08aff1923f40902d24d74b02204c42443de23f8b4004f6cca592c5b4243a80bd95a644561f5b5237fe7b852ea4:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.