PT-2019-6331 · Inspur · Inspur Clusterengine

Published

2019-11-26

·

Updated

2021-02-26

·

CVE-2020-21224

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Inspur ClusterEngine version V4.0
Description A Remote Code Execution issue has been found, allowing a remote attacker to send a malicious login packet to the control server. The vulnerability is related to the injection or modification of arguments with the ' parameter, which can be exploited by sending specially crafted packets, enabling the attacker to execute arbitrary code.
Recommendations For Inspur ClusterEngine version V4.0, consider disabling the login functionality until a patch is available. Restrict access to the control server to minimize the risk of exploitation. Avoid using the vulnerable parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02310
CVE-2020-21224

Affected Products

Inspur Clusterengine