Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-22153

Опубликовано: 13 мая 2021
Источник: nvd
CVSS3: 7.3
CVSS2: 6
EPSS Низкий

Описание

A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine with the authority of the user.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:blackberry:unified_endpoint_management:*:*:*:*:*:*:*:*
Версия до 12.12.0 (включая)
cpe:2.3:a:blackberry:unified_endpoint_management:12.12.1a:quick_fix_1:*:*:*:*:*:*
cpe:2.3:a:blackberry:unified_endpoint_management:12.12.1a:quick_fix_2:*:*:*:*:*:*
cpe:2.3:a:blackberry:unified_endpoint_management:12.12.1a:quick_fix_3:*:*:*:*:*:*
cpe:2.3:a:blackberry:unified_endpoint_management:12.12.1a:quick_fix_4:*:*:*:*:*:*
cpe:2.3:a:blackberry:unified_endpoint_management:12.12.1a:quick_fix_5:*:*:*:*:*:*
cpe:2.3:a:blackberry:unified_endpoint_management:12.12.1a:quick_fix_6:*:*:*:*:*:*
cpe:2.3:a:blackberry:unified_endpoint_management:12.13.0:-:*:*:*:*:*:*
cpe:2.3:a:blackberry:unified_endpoint_management:12.13.0:mr1:*:*:*:*:*:*
cpe:2.3:a:blackberry:unified_endpoint_management:12.13.1:quick_fix_1:*:*:*:*:*:*
cpe:2.3:a:blackberry:unified_endpoint_management:12.13.1:quick_fix_2:*:*:*:*:*:*

EPSS

Процентиль: 70%
0.00651
Низкий

7.3 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-1236

Связанные уязвимости

github
больше 3 лет назад

A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine with the authority of the user.

EPSS

Процентиль: 70%
0.00651
Низкий

7.3 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-1236