Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2021-21385

8.8 · HIGH
Published Mar 24, 2021 mifos CWE-295 EPSS 0.70% (51th pctl)

Overview

CVE-2021-21385 is a high-severity vulnerability affecting mifos mifos-mobile. It was published on March 24, 2021 and has a CVSS 3.1 base score of 8.8 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.8, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

Mifos-Mobile Android Application for MifosX is an Android Application built on top of the MifosX Self-Service platform. Mifos-Mobile before commit e505f62 disables HTTPS hostname verification of its HTTP client. Additionally it accepted any self-signed certificate as valid. Hostname verification is an important part when using HTTPS to ensure that the presented certificate is valid for the host. Disabling it can allow for man-in-the-middle attacks. Accepting any certificate, even self-signed ones allows man-in-the-middle attacks. This problem is fixed in mifos-mobile commit e505f62.

Remediation

Check the references section for vendor advisories and patches from mifos. Update mifos-mobile to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
mifos mifos-mobile >= 0, < 2021-03-14 Affected

Frequently Asked Questions

What is CVE-2021-21385?

CVE-2021-21385 is a high-severity vulnerability affecting mifos mifos-mobile. It was published on March 24, 2021 and has a CVSS 3.1 base score of 8.8 (HIGH).

How severe is CVE-2021-21385?

This vulnerability has a CVSS 3.1 base score of 8.8, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2021-21385?

Check the references section for vendor advisories and patches from mifos. Update mifos-mobile to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2021-21385?

CyberStrike's AI-powered security agents can automatically detect CVE-2021-21385 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.