PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-44793 Krontech CVE debrief

A missing authorization check in Krontech Single Connect's sc-reports-ui module allows unauthenticated remote attackers to access device configuration pages and export sensitive data, including database credentials. The vulnerability was disclosed in January 2022 and affects versions prior to 2.16.

Vendor
Krontech
Product
Single Connect
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2022-01-27
Original CVE updated
2026-05-18
Advisory published
2022-01-27
Advisory updated
2026-05-18

Who should care

Organizations running Krontech Single Connect for privileged access management; security teams monitoring for unauthorized configuration access; database administrators responsible for credential security and privilege separation.

Technical summary

The sc-reports-ui module in Krontech Single Connect fails to enforce authorization checks on requests to access the device configuration page. An unauthenticated remote attacker can directly access this functionality and export configuration data to an external file. The exported data contains database credentials; the database operates with elevated privileges, enabling command execution through credential misuse. The vulnerability is classified as CWE-862 (Missing Authorization) with a CVSS 3.1 score of 8.6 (High severity).

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade Krontech Single Connect to version 2.16 or later to remediate the missing authorization check in the sc-reports-ui module.
  • Restrict network access to Single Connect administrative interfaces to trusted administrative hosts only.
  • Monitor for unauthorized access attempts to /sc-reports-ui/ paths and configuration export endpoints.
  • Audit database credential rotation if compromise is suspected, as the vulnerability exposes credentials that could enable command execution via the privileged database account.
  • Review application logs for unexpected configuration exports or data exfiltration activity predating 2022-01-27.

Evidence notes

Official disclosure from Turkish National Cyber Security Incident Response Center (USOM) via NVD. CVSS 3.1 vector confirms network attack vector with no privileges required. CPE criteria specifies affected product as Krontech Single Connect versions before 2.16.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-44793 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-44793

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-44793 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-44793

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.