Vulnerabilities > CVE-2021-38617 - Unspecified vulnerability in Eigentech Natural Language Processing 3.10.1

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
eigentech

Summary

In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/ user creation endpoint allows a standard user to create a super user account with a defined password. This directly leads to privilege escalation.

Vulnerable Configurations

Part Description Count
Application
Eigentech
1