CVE-2021-26724
Last modified
CVE-2021-26724 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. EPSS estimates a 3.07% chance of exploitation in the next 30 days.
Description
OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nozominetworks | Central Management Control | >= 19.0.0, <= 19.0.12 |
| Nozominetworks | Central Management Control | >= 20.0.0.0, < 20.0.7.4 |
| Nozominetworks | Guardian | >= 19.0.0, < 19.0.12 |
| Nozominetworks | Guardian | >= 20.0.0.0, < 20.0.7.4 |
References
- https://security.nozominetworks.com/NN-2021:1-01Vendor Advisory
- https://security.nozominetworks.com/NN-2021:1-01Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-26724?
How severe is CVE-2021-26724?
How do I fix CVE-2021-26724?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-26717An issue was discovered in Sangoma Asterisk 16.x before 16.1…7.5
- CVE-2021-26718KIS for macOS in some use cases was vulnerable to AV bypass …5.5
- CVE-2021-26719A directory traversal issue was discovered in Gradle gradle-…6.5
- CVE-2021-26720avahi-daemon-check-dns.sh in the Debian avahi package throug…7.8
- CVE-2021-26722LinkedIn Oncall through 1.4.0 allows reflected XSS via /quer…6.1
- CVE-2021-26723Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= …6.1
- CVE-2021-26725Path Traversal vulnerability when changing timezone using we…4.9
- CVE-2021-26726A remote code execution vulnerability affecting a Valmet DNA…8.8
- CVE-2021-26727Multiple command injections and stack-based buffer overflows…9.8
- CVE-2021-26728Command injection and stack-based buffer overflow vulnerabil…9.8
- CVE-2021-26729Command injection and multiple stack-based buffer overflows …9.8
- CVE-2021-26730A stack-based buffer overflow vulnerability in a subfunction…9.8
Are you affected by CVE-2021-26724?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
