ZeroHour

CVE-2021-26622

CVSS 3.1
10.0 critical
EPSS
3%p87
Published
()
Modified
Description

An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability.

Vendors
genians
Products
genian nac
Weakness
CWE-20, CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.