8 results (0.004 seconds)

CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 0

An administrator is able to execute commands as root via the alerts management dialog • https://csirt.divd.nl/CVE-2021-4406 https://www.divd.nl/DIVD-2021-00020 https://www.osnexus.com/products/software-defined-storage https://csirt.divd.nl/DIVD-2021-00020 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 0

An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. • https://csirt.divd.nl/CVE-2021-42081 https://www.divd.nl/DIVD-2021-00020 https://www.osnexus.com/products/software-defined-storage https://www.wbsec.nl/osnexus https://csirt.divd.nl/DIVD-2021-00020 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 6.2EPSS: 0%CPEs: 1EXPL: 0

An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with POST requests. • https://csirt.divd.nl/CVE-2021-42079 https://www.divd.nl/DIVD-2021-00020 https://www.osnexus.com/products/software-defined-storage https://www.wbsec.nl/osnexus https://cisrt.divd.nl/DIVD-2021-00020 • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 7.4EPSS: 0%CPEs: 1EXPL: 0

An attacker is able to launch a Reflected XSS attack using a crafted URL. • https://csirt.divd.nl/CVE-2021-42080 https://www.divd.nl/DIVD-2021-00020 https://www.osnexus.com/products/software-defined-storage https://www.wbsec.nl/osnexus https://csirt.divd.nl/DIVD-2021-00020 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

Local users are able to execute scripts under root privileges. • https://csirt.divd.nl/CVE-2021-42082 https://www.divd.nl/DIVD-2021-00020 https://www.osnexus.com/products/software-defined-storage https://www.wbsec.nl/osnexus https://csirt.divd.nl/DIVD-2021-00020 • CWE-269: Improper Privilege Management •