PT-2021-23271 · Device42 · Device42 Main Appliance

Published

2021-09-17

·

Updated

2021-09-30

·

CVE-2021-41316

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Device42 Main Appliance versions prior to 17.05.01
Description The issue concerns the Nmap Discovery utility in the Device42 Main Appliance, which does not properly sanitize user input. This allows an attacker with permissions to add or edit jobs run by this utility to inject an extra argument, potentially overwriting arbitrary files as the root user on the Remote Collector.
Recommendations For versions prior to 17.05.01, update to version 17.05.01 or later to resolve the issue. As a temporary workaround, consider restricting access to the Nmap Discovery utility and limiting permissions for adding or editing jobs to minimize the risk of exploitation.

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41316

Affected Products

Device42 Main Appliance