PT-2021-14752 · Zte · Zte Conference Management System

Published

2021-08-30

·

Updated

2023-06-06

·

CVE-2021-21741

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZTE conference management system (affected versions not specified)
Description The issue concerns a command execution vulnerability. It allows an attacker to execute arbitrary commands by sending specific serialization commands, taking advantage of services that are enabled by default.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2021-21741

Affected Products

Zte Conference Management System