CVE-2021-33527
OS Command Injection in mbDIALUP <= 3.9R0.0
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In MB connect line mbDIALUP versions <= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORITY\SYSTEM that will not correctly validate the input. This can lead to an arbitrary code execution with the privileges of the service.
En las versiones de MB connect line mbDIALUP versiones anteriores o iguales a 3.9R0.0 un atacante remoto puede enviar una petición HTTP específicamente diseñada al servicio que se ejecuta con NT AUTHORITY\SYSTEM que no valide correctamente la entrada. Esto puede llevar a una ejecución de código arbitrario con los privilegios del servicio
*Credits:
Noam Moshe of Claroty reported this vulnerability to MB connect line GmbH. CERT@VDE coordinated.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-05-24 CVE Reserved
- 2021-08-02 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://cert.vde.com/de-de/advisories/vde-2021-017 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mbconnectline Search vendor "Mbconnectline" | Mbdialup Search vendor "Mbconnectline" for product "Mbdialup" | <= 3.9r0.0 Search vendor "Mbconnectline" for product "Mbdialup" and version " <= 3.9r0.0" | - |
Affected
|