ZeroHour

CVE-2021-26914

PoC ×3
CVSS 3.1
8.1 high
EPSS
78%p100
Published
()
Modified
Description

NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.

Vendors
netmotionsoftware
Products
netmotion mobility
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.