Skip to main content

CVE-2021-23196

7.3
HIGHCVSS v3.1 Base Score
0.26%
LOW RiskEPSS (50th percentile)

The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attributes sufficiently.

Published: 1/21/2022
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.3HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CVSS v2 Score

7.5

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

0.26%LOW Exploitation Risk
50th percentile

This vulnerability has a 0.26% probability of being exploited in the next 30 days, ranking higher than 50% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-522)

CVE-2025-54863CRITICAL 10

Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration file. This allows attackers to remotely alter weather data and configurations, automate attacks against multiple instances, and extract sensitive meteorological data, which could potentially compromise airport operations. Additionally, attackers could flood the system with false alerts, leading to a denial-of-service condition and significant disruption to airport operations. Unauthorized remote control over aviation weather monitoring and data manipulation could result in incorrect flight planning and hazardous takeoff and landing conditions.

11/4/2025
CVE-2025-6519CRITICAL 9.8

E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user.

9/2/2025
CVE-2025-52549CRITICAL 9.8

E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters.

9/2/2025
CVE-2025-26492HIGH 7.7

In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources

2/11/2025
CVE-2025-0498CRITICAL 9.8

A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user.

1/30/2025

Similar SeverityHIGH