CVE-2021-26622
—CVSS 3.1
10.0 critical
EPSS
3%p87
Published
()
Modified
Description
An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability.
- Vendors
- genians
- Products
- genian nac
- Weakness
- CWE-20, CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.