CVE-2021-35060 is a medium-severity vulnerability affecting OpenWay WAY4 ACS versions prior to 1.2.278-2693. It allows unauthenticated attackers to determine if a specific payment card number exists in the system by observing differences in application responses. The vulnerability has a CVSS score of 5.3, indicating a low impact on confidentiality with no integrity or availability impact, and requires no user interaction. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the CISA KEV catalog, suggesting no active exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.278-2693CPE matchmatch criteria | cpe:2.3:a:openwaygroup:way4:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.