#VU52976 Insecure configuration in Reticulum - CVE-2021-29954 

 

#VU52976 Insecure configuration in Reticulum - CVE-2021-29954

Published: May 7, 2021


Vulnerability identifier: #VU52976
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2021-29954
CWE-ID: CWE-16
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Reticulum
Software vendor:
Mozilla

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insecure proxy configuration built into our Reticulum software package, which allowed access to internal URLs, including the metadata service, which could allow access to credentials specific to a Hubs Cloud Instance. A remote non-authenticated attacker can obtain sensitive information and use it to compromise the Hubs Cloud Instance.


Remediation

Install updates from vendor's website.

External links