CVE-2021-20740

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
28/06/2021
Last modified:
06/07/2021

Description

Hitachi Virtual File Platform Versions prior to 5.5.3-09 and Versions prior to 6.4.3-09, and NEC Storage M Series NAS Gateway Nh4a/Nh8a versions prior to FOS 5.5.3-08(NEC2.5.4a) and Nh4b/Nh8b, Nh4c/Nh8c versions prior to FOS 6.4.3-08(NEC3.4.2) allow remote authenticated attackers to execute arbitrary OS commands with root privileges via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hitachi:virtual_file_platform:*:*:*:*:*:*:*:* 6.4.3-09 (excluding)
cpe:2.3:a:hitachi:virtual_file_platform:*:*:*:*:*:*:*:* 5.5.3-09 (excluding)
cpe:2.3:o:nec:nas_gateway_nh4a_firmware:*:*:*:*:*:*:*:* fos_5.5.3-08\(nec2.5.4a\) (excluding)
cpe:2.3:h:nec:nas_gateway_nh4a:-:*:*:*:*:*:*:*
cpe:2.3:o:nec:nas_gateway_nh8a_firmware:*:*:*:*:*:*:*:* fos_5.5.3-08\(nec2.5.4a\) (excluding)
cpe:2.3:h:nec:nas_gateway_nh8a:-:*:*:*:*:*:*:*
cpe:2.3:o:nec:nas_gateway_nh4b_firmware:*:*:*:*:*:*:*:* fos_6.4.3-08\(nec3.4.2\) (excluding)
cpe:2.3:h:nec:nas_gateway_nh4b:-:*:*:*:*:*:*:*
cpe:2.3:o:nec:nas_gateway_nh8b_firmware:*:*:*:*:*:*:*:* fos_6.4.3-08\(nec3.4.2\) (excluding)
cpe:2.3:h:nec:nas_gateway_nh8b:-:*:*:*:*:*:*:*
cpe:2.3:o:nec:nas_gateway_nh4c_firmware:*:*:*:*:*:*:*:* fos_6.4.3-08\(nec3.4.2\) (excluding)
cpe:2.3:h:nec:nas_gateway_nh4c:-:*:*:*:*:*:*:*
cpe:2.3:o:nec:nas_gateway_nh8c_firmware:*:*:*:*:*:*:*:* fos_6.4.3-08\(nec3.4.2\) (excluding)
cpe:2.3:h:nec:nas_gateway_nh8c:-:*:*:*:*:*:*:*