← back
CVE-2021-38120mediumCWE-77

Remote Code Execution using Bash command Injection in backup scheduling functionality in NetIQ Advance Authentication

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.1epss 0.5%
exploitation probability
0.5%top 58% of all CVEs
observed exploitation
nono source reports it
A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1.
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:L