CVE-2021-41554 is a critical access control vulnerability affecting ARCHIBUS Web Central version 21.3.3.815 and earlier, allowing authenticated users to bypass permission checks and access administrative functions. With a CVSS score of 8.8 (HIGH), an attacker can achieve full compromise of user accounts, including privilege escalation to administrative levels, and user creation/deletion. While no public exploits or active exploitation have been observed, and community discussion is minimal, the vulnerability's impact is severe for organizations still using this unsupported software version.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
21.3.3.815CPE matchmatch criteria | cpe:2.3:a:archibus:web_central:21.3.3.815:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.