CVE-2021-29644
Severity CVSS v4.0:
Pending analysis
Type:
CWE-190
Integer Overflow or Wraparound
Publication date:
12/10/2021
Last modified:
20/10/2021
Description
Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the underlying OS.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:hitachi:it_operations_director:*:*:*:*:*:*:*:* | 02-50 (including) | 02-50-07 (including) |
| cpe:2.3:a:hitachi:it_operations_director:*:*:*:*:*:*:*:* | 03-00 (including) | 03-00-12 (including) |
| cpe:2.3:a:hitachi:it_operations_director:*:*:*:*:*:*:*:* | 04-00 (including) | 04-00-17 (including) |
| cpe:2.3:a:hitachi:it_operations_director:*:*:*:*:*:*:*:* | 04-50 (including) | 04-50-16 (including) |
| cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* | 09-50 (including) | 09-50-03 (including) |
| cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* | 10-01 (including) | 10-01-06 (including) |
| cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* | 10-10 (including) | 10-10-16 (including) |
| cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management_2-manager:*:*:*:*:*:*:*:* | 10-50 (including) | 10-50-11 (including) |
| cpe:2.3:a:hitachi:job_management_partner_1\/remote_control_agent:*:*:*:*:*:*:*:* | 08-00 (including) | 08-00-04 (including) |
| cpe:2.3:a:hitachi:job_management_partner_1\/remote_control_agent:*:*:*:*:*:*:*:* | 08-10 (including) | 08-10-05 (including) |
| cpe:2.3:a:hitachi:job_management_partner_1\/remote_control_agent:*:*:*:*:*:*:*:* | 08-51 (including) | 08-51-18 (including) |
| cpe:2.3:a:hitachi:job_management_partner_1\/remote_control_agent:*:*:*:*:*:*:*:* | 09-00 (including) | 09-00-07 (including) |
| cpe:2.3:a:hitachi:job_management_partner_1\/remote_control_agent:*:*:*:*:*:*:*:* | 09-50 (including) | 09-50-09 (including) |
| cpe:2.3:a:hitachi:job_management_partner_1\/remote_control_agent:*:*:*:*:*:*:*:* | 09-51 (including) | 09-51-15 (including) |
| cpe:2.3:a:hitachi:job_management_partner_1\/software_distribution_client:*:*:*:*:*:*:*:* | 08-00 (including) | 08-00-05 (including) |
To consult the complete list of CPE names with products and versions, see this page



