HIGH🇬🇧 English

CVE-2021-42372

CVSS 8.8v3.1pub. 2021-11-08upd. 2024-11-21

A shell command injection in the HW Events SNMP community in XoruX LPAR2RRD and STOR2RRD before 7.30 allows authenticated remote attackers to execute arbitrary shell commands as the user running the service.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Xorux Lpar2rrd

    APP
    Xorux
    < 7.30
  • Xorux Stor2rrd

    APP
    Xorux
    < 7.30
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Command Injection
CWE
Referencje

Powiązane podatności

CVE-2021-42371CRITICAL9.8PL ✓ten sam produkt

Hardkodowane konto systemowe w XoruX LPAR2RRD i STOR2RRD

CVE-2020-24032CRITICAL9.8PL ✓ten sam produkt

Command injection w XoruX LPAR2RRD i STOR2RRD przez parametr strefy czasowej

CVE-2014-4981CRITICAL9.8PL ✓ten sam produkt

Command Injection w LPAR2RRD — zdalne wykonanie poleceń systemowych

CVE-2014-4982CRITICAL9.8PL ✓ten sam produkt

Command injection w Xorux LPAR2RRD — zdalne wykonanie poleceń

CVE-2025-54769HIGH8.8ten sam produkt

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file...