CVE-2021-4471
BaseFortify
Publication date: 2025-11-14
Last updated on: 2025-11-17
Assigner: VulnCheck
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tg8 | firewall | 4.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-538 | The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the TG8 Firewall exposing a directory such as /data/ over HTTP without requiring authentication. This directory contains credential files for users who have previously logged in. Because it is accessible without authentication, a remote attacker can enumerate and download these files to obtain valid usernames and passwords.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability can gain access to valid account usernames and passwords, leading to loss of confidentiality and potentially further unauthorized access to the system or network protected by the TG8 Firewall.