Message Authentication Bypass in Cleo LexiCom by Cleo
CVE-2021-33577
5.3MEDIUM
What is CVE-2021-33577?
In Cleo LexiCom version 5.5.0.0, a vulnerability allows an attacker to bypass the requirement for AS2 message authentication. This is achieved by altering the message's Content-Type to text/plain, which undermines the intended security measures of sender identification through encryption and signing. Without appropriate safeguarding, this flaw can expose sensitive data to unauthorized access, emphasizing the necessity for immediate remediation to secure message exchanges.
