PT-2022-9771 · Genians · Genian Nac

Published

2022-03-25

·

Updated

2023-06-26

·

CVE-2021-26622

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Genian NAC (affected versions not specified)
Description A remote code execution issue was discovered due to a Server-Side Template Injection (SSTI) vulnerability and insufficient validation of the file name parameter. This allows remote attackers to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-26622

Affected Products

Genian Nac