PT-2021-19968 · Zstack · Z-Stack

Alvaro Muñoz

+1

·

Published

2021-09-09

·

Updated

2022-04-25

·

CVE-2021-32836

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZStack versions prior to 3.10.12 ZStack versions prior to 4.1.6
Description The issue is related to a pre-auth unsafe deserialization vulnerability in the REST API. An attacker controlling the request body can provide the class name and data to be deserialized, allowing instantiation of an arbitrary type and assignment of arbitrary values to its fields. This may lead to a Denial Of Service. If a suitable gadget is available, an attacker may also be able to exploit this vulnerability to gain pre-auth remote code execution.
Recommendations For versions prior to 3.10.12, update to version 3.10.12 or later. For versions prior to 4.1.6, update to version 4.1.6 or later.

Exploit

Fix

Deserialization of Untrusted Data

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32836
GHSA-JFVQ-548H-342X

Affected Products

Z-Stack