PT-2019-6331 · Inspur · Inspur Clusterengine
Published
2019-11-26
·
Updated
2021-02-26
·
CVE-2020-21224
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Inspur ClusterEngine version V4.0
Description
A Remote Code Execution issue has been found, allowing a remote attacker to send a malicious login packet to the control server. The vulnerability is related to the injection or modification of arguments with the
' parameter, which can be exploited by sending specially crafted packets, enabling the attacker to execute arbitrary code.Recommendations
For Inspur ClusterEngine version V4.0, consider disabling the login functionality until a patch is available. Restrict access to the control server to minimize the risk of exploitation. Avoid using the vulnerable parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Inspur Clusterengine