CVE-2021-26622
Published: Mar 25, 2022
Modified: Aug 3, 2024
CVSS v3.1
9.6
Description
An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability.
| Vendor | Product | Versions |
|---|---|---|
Genians Co., Ltd | Genian NAC Suite V4.0 | affected unspecified - <= 4.0.145.0831 |
Genians Co., Ltd | Genian NAC V5.0 & Genian NAC Suite V5.0 | affected unspecified - <= 5.0.42.0827 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now