{"id":"CVE-2021-28979","title":"SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks","summary":"SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is …","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","cwe":["CWE-74"],"vendor":"thalesgroup","product":"safenet_keysecure","affected":["safenet_keysecure <= 8.12.0"],"published":"2021-06-16","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-28979","references":[{"url":"https://www.gruppotim.it/redteam","label":"cve@mitre.org"},{"url":"https://www.thalesgroup.com/en","label":"nvd@nist.gov"},{"url":"http://safenet.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://thales.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.gruppotim.it/redteam","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01178,"epssPercentile":0.66322,"ingestedAt":"2026-07-06T01:08:16.752Z","slug":"CVE-2021-28979","body":"## Overview\n\nSafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked.\n\n## Affected\n\n- `safenet_keysecure <= 8.12.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}