← back
CVE-2021-38120

Remote Code Execution using Bash command Injection in backup scheduling functionality in NetIQ Advance Authentication

CVSS 5.1 MEDIUMEPSS 0.5%CWE-77
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.1EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
28 Aug 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1.
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →