HIGH🇵🇱 Wersja polska

CVE-2021-42372

CVSS 8.8v3.1pub. 2021-11-08upd. 2024-11-21

A shell command injection in the HW Events SNMP community in XoruX LPAR2RRD and STOR2RRD before 7.30 allows authenticated remote attackers to execute arbitrary shell commands as the user running the service.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Xorux Lpar2rrd

    APP
    Xorux
    < 7.30
  • Xorux Stor2rrd

    APP
    Xorux
    < 7.30
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2021-42371CRITICAL9.8PL ✓same product

Hardkodowane konto systemowe w XoruX LPAR2RRD i STOR2RRD

CVE-2020-24032CRITICAL9.8PL ✓same product

Command injection w XoruX LPAR2RRD i STOR2RRD przez parametr strefy czasowej

CVE-2014-4981CRITICAL9.8PL ✓same product

Command Injection w LPAR2RRD — zdalne wykonanie poleceń systemowych

CVE-2014-4982CRITICAL9.8PL ✓same product

Command injection w Xorux LPAR2RRD — zdalne wykonanie poleceń

CVE-2025-54769HIGH8.8same product

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file...