CVE-2021-28818Improper Privilege Management in Software INC Tibco Rendezvous

Severity
7.8HIGHNVD
CNA8.8
EPSS
0.1%
top 84.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23
Latest updateMay 24

Description

The Rendezvous Routing Daemon (rvrd), Rendezvous Secure Routing Daemon (rvrsd), Rendezvous Secure Daemon (rvsd), Rendezvous Cache (rvcache), Rendezvous Secure C API, Rendezvous Java API, and Rendezvous .Net API components of TIBCO Software Inc.'s TIBCO Rendezvous and TIBCO Rendezvous Developer Edition contain a vulnerability that theoretically allows a low privileged attacker with local access on the Windows operating system to insert malicious software. The affected component can be abused to e

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5tibco_software_inc/tibco_rendezvousunspecified8.5.1
NVDtibco/rendezvous8.5.1

🔴Vulnerability Details

2
GHSA
GHSA-cqv6-cx7q-c7w5: The Rendezvous Routing Daemon (rvrd), Rendezvous Secure Routing Daemon (rvrsd), Rendezvous Secure Daemon (rvsd), Rendezvous Cache (rvcache), Rendezvou2022-05-24
CVEList
TIBCO Rendezvous Windows Platform Artifact Search vulnerability2021-03-23
CVE-2021-28818 — Improper Privilege Management | cvebase