CVE-2021-32794
NixOS vulnerability analysis and mitigation

Overview

Due to a bug in ASF (ArchiSteamFarm) code, the POST /Api/ASF ASF API endpoint responsible for updating global ASF config incorrectly removed IPCPassword from the resulting config when the caller did not specify it explicitly. This vulnerability was discovered in July 2021 and affected versions prior to 5.1.2.4. The vulnerability is tracked as CVE-2021-32794 and has been assigned a CVSS score of 6.8 (Moderate) (GitHub Advisory).

Technical details

The vulnerability occurred when updating the global ASF configuration through the API endpoint. When a user made changes to the global config without explicitly specifying the IPCPassword, the system would incorrectly remove the password instead of preserving it. This behavior was specific to the IPCPassword property, while other sensitive properties like SteamLogin or SteamPassword remained unaffected (GitHub Advisory).

Impact

The removal of IPCPassword could expose the IPC interface to unauthorized access. While the vulnerability required an initially authorized user to trigger the bug, it could lead to security risks by accidentally removing the authentication mechanism protecting the IPC interface. The issue primarily affected users who were using ASF on VPS with IPC server behind a reverse proxy (GitHub Advisory, Steam Discussion).

Exploitability

The vulnerability could not be exploited remotely without prior authorization. An attacker would need to have valid authentication credentials to trigger the bug. The issue was particularly concerning for users who were using ASF-ui's global config update functionality (GitHub PR).

Mitigation and workarounds

The issue was patched in ASF version 5.1.2.4 and later versions. Users are recommended to manually verify that IPCPassword is specified after updating. For those unable to upgrade, workarounds include refraining from using POST /Api/ASF endpoint, not using ASF-ui global config update functionality, or manually resetting IPCPassword after any configuration changes. By default, ASF is configured to allow IPC access from localhost only, which limits the vulnerability's scope (GitHub Advisory).

Community reactions

The issue was initially reported in the Steam community forums, where users reported instances of inventory theft potentially linked to this vulnerability. The development team responded promptly by investigating the reports and implementing fixes (Steam Discussion).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78662HIGH7.5
  • Terraform Community logoTerraform Community
  • argo-workflow-controller-fips-4.0
NoYesSep 02, 2026
CVE-2026-56855HIGH7.5
  • Terraform Community logoTerraform Community
  • prometheus-mongodb-exporter-0.37
NoYesSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-84640HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management