9.3
CVE-2021-26912
- EPSS 35.43%
- Veröffentlicht 08.02.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:57:01
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netmotionsoftware ≫ Netmotion Mobility Version < 11.73
Netmotionsoftware ≫ Netmotion Mobility Version >= 12.0 < 12.02
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 35.43% | 0.969 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.