Логотип exploitDog
bind:CVE-2021-34996
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-34996

Количество 3

Количество 3

nvd логотип

CVE-2021-34996

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Demo_ExecuteProcessOnGroup workflow. By creating a workflow, an attacker can specify an arbitrary command to be executed. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-13889.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-f572-r3rr-hjcx

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Demo_ExecuteProcessOnGroup workflow. By creating a workflow, an attacker can specify an arbitrary command to be executed. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-13889.

EPSS: Средний
fstec логотип

BDU:2022-00087

больше 4 лет назад

Уязвимость процесса Demo_ExecuteProcessOnGroup программного средства управления хранилищем CommCell, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-34996

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Demo_ExecuteProcessOnGroup workflow. By creating a workflow, an attacker can specify an arbitrary command to be executed. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-13889.

CVSS3: 8.8
20%
Средний
около 4 лет назад
github логотип
GHSA-f572-r3rr-hjcx

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Demo_ExecuteProcessOnGroup workflow. By creating a workflow, an attacker can specify an arbitrary command to be executed. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-13889.

20%
Средний
около 4 лет назад
fstec логотип
BDU:2022-00087

Уязвимость процесса Demo_ExecuteProcessOnGroup программного средства управления хранилищем CommCell, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
20%
Средний
больше 4 лет назад

Уязвимостей на страницу