10

CVE-2021-42237

Warnung
Exploit
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sitecore ≫ Experience Platform Version 7.5 Update -
Sitecore ≫ Experience Platform Version 7.5 Update update1
Sitecore ≫ Experience Platform Version 7.5 Update update2
Sitecore ≫ Experience Platform Version 8.0 Update -
Sitecore ≫ Experience Platform Version 8.0 Update sp1
Sitecore ≫ Experience Platform Version 8.0 Update update1
Sitecore ≫ Experience Platform Version 8.0 Update update2
Sitecore ≫ Experience Platform Version 8.0 Update update3
Sitecore ≫ Experience Platform Version 8.0 Update update4
Sitecore ≫ Experience Platform Version 8.0 Update update5
Sitecore ≫ Experience Platform Version 8.0 Update update6
Sitecore ≫ Experience Platform Version 8.0 Update update7
Sitecore ≫ Experience Platform Version 8.1 Update -
Sitecore ≫ Experience Platform Version 8.1 Update update1
Sitecore ≫ Experience Platform Version 8.1 Update update2
Sitecore ≫ Experience Platform Version 8.1 Update update3
Sitecore ≫ Experience Platform Version 8.2 Update -
Sitecore ≫ Experience Platform Version 8.2 Update update1
Sitecore ≫ Experience Platform Version 8.2 Update update2
Sitecore ≫ Experience Platform Version 8.2 Update update3
Sitecore ≫ Experience Platform Version 8.2 Update update4
Sitecore ≫ Experience Platform Version 8.2 Update update5
Sitecore ≫ Experience Platform Version 8.2 Update update6
Sitecore ≫ Experience Platform Version 8.2 Update update7

25.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Sitecore XP Remote Command Execution Vulnerability

Schwachstelle

Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 97.9% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://blog.assetnote.io/2021/11/02/sitecore-rce/
Third Party Advisory
Exploit
http://packetstormsecurity.com/files/164988/Sitecore-Experience-Platform-XP-Remote-Code-Execution.html
Third Party Advisory
VDB Entry
https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1000776
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-42237
US Government Resource