CVE-2021-26622

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
25/03/2022
Last modified:
26/06/2023

Description

An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:genians:genian_nac:*:*:*:*:*:*:*:* 4.0 (including) 4.0.145.0831 (including)
cpe:2.3:a:genians:genian_nac:*:*:*:*:*:*:*:* 5.0 (including) 5.0.42.0827 (including)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*