PatchSiren cyber security CVE debrief
CVE-2021-44793 Krontech CVE debrief
A missing authorization check in Krontech Single Connect's sc-reports-ui module allows unauthenticated remote attackers to access device configuration pages and export sensitive data, including database credentials. The vulnerability was disclosed in January 2022 and affects versions prior to 2.16.
- Vendor
- Krontech
- Product
- Single Connect
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2022-01-27
- Original CVE updated
- 2026-05-18
- Advisory published
- 2022-01-27
- Advisory updated
- 2026-05-18
Who should care
Organizations running Krontech Single Connect for privileged access management; security teams monitoring for unauthorized configuration access; database administrators responsible for credential security and privilege separation.
Technical summary
The sc-reports-ui module in Krontech Single Connect fails to enforce authorization checks on requests to access the device configuration page. An unauthenticated remote attacker can directly access this functionality and export configuration data to an external file. The exported data contains database credentials; the database operates with elevated privileges, enabling command execution through credential misuse. The vulnerability is classified as CWE-862 (Missing Authorization) with a CVSS 3.1 score of 8.6 (High severity).
Defensive priority
HIGH
Recommended defensive actions
- Upgrade Krontech Single Connect to version 2.16 or later to remediate the missing authorization check in the sc-reports-ui module.
- Restrict network access to Single Connect administrative interfaces to trusted administrative hosts only.
- Monitor for unauthorized access attempts to /sc-reports-ui/ paths and configuration export endpoints.
- Audit database credential rotation if compromise is suspected, as the vulnerability exposes credentials that could enable command execution via the privileged database account.
- Review application logs for unexpected configuration exports or data exfiltration activity predating 2022-01-27.
Evidence notes
Official disclosure from Turkish National Cyber Security Incident Response Center (USOM) via NVD. CVSS 3.1 vector confirms network attack vector with no privileges required. CPE criteria specifies affected product as Krontech Single Connect versions before 2.16.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-44793 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-44793
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-44793 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-44793
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-22-0093
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-22-0093
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.