PT-2021-23271 · Device42 · Device42 Main Appliance
Published
2021-09-17
·
Updated
2021-09-30
·
CVE-2021-41316
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Device42 Main Appliance versions prior to 17.05.01
Description
The issue concerns the Nmap Discovery utility in the Device42 Main Appliance, which does not properly sanitize user input. This allows an attacker with permissions to add or edit jobs run by this utility to inject an extra argument, potentially overwriting arbitrary files as the root user on the Remote Collector.
Recommendations
For versions prior to 17.05.01, update to version 17.05.01 or later to resolve the issue. As a temporary workaround, consider restricting access to the Nmap Discovery utility and limiting permissions for adding or editing jobs to minimize the risk of exploitation.
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Device42 Main Appliance