← back
CVE-2021-21315highunder attackCWE-78

Command Injection Vulnerability

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.1epss 91%
from disclosure to weapon13 days
Published on NVDFeb 16
1st PoC+13d
CISA KEV+336d
exploitation probability
91%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
8 public exploit(s)
Action required by CISAfederal deadline: 2022-02-01

Apply updates per vendor instructions.

Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.