PT-2021-15218 · Unknown · Connexium Network Manager

Published

2021-10-19

·

Updated

2022-02-22

·

CVE-2021-22801

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ConneXium Network Manager Software (All Versions)
Description A vulnerability exists due to improper privilege management, which could lead to arbitrary command execution when the software is configured with specially crafted event actions.
Recommendations For all versions, consider restricting access to event action configurations to minimize the risk of exploitation until a patch is available. As a temporary workaround, review and validate all existing event actions to ensure they are not specially crafted to execute arbitrary commands.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22801
ZDI-21-1212

Affected Products

Connexium Network Manager