PT-2021-15218 · Unknown · Connexium Network Manager
Published
2021-10-19
·
Updated
2022-02-22
·
CVE-2021-22801
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ConneXium Network Manager Software (All Versions)
Description
A vulnerability exists due to improper privilege management, which could lead to arbitrary command execution when the software is configured with specially crafted event actions.
Recommendations
For all versions, consider restricting access to event action configurations to minimize the risk of exploitation until a patch is available.
As a temporary workaround, review and validate all existing event actions to ensure they are not specially crafted to execute arbitrary commands.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connexium Network Manager