CVE-2021-29644

CRITICALCVSS 9.8/10EPSS 2.45%

Last modified

CVE-2021-29644 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the underlying OS.. EPSS estimates a 2.45% chance of exploitation in the next 30 days.

Description

Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the underlying OS.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
2.45%

82.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HitachiIt Operations Director>= 02-50, <= 02-50-07
HitachiIt Operations Director>= 03-00, <= 03-00-12
HitachiIt Operations Director>= 04-00, <= 04-00-17
HitachiIt Operations Director>= 04-50, <= 04-50-16
HitachiJob Management Partner 1\/It Desktop Management-Manager>= 09-50, <= 09-50-03
HitachiJob Management Partner 1\/It Desktop Management-Manager>= 10-01, <= 10-01-06
HitachiJob Management Partner 1\/It Desktop Management-Manager>= 10-10, <= 10-10-16
HitachiJob Management Partner 1\/It Desktop Management 2-Manager>= 10-50, <= 10-50-11
HitachiJob Management Partner 1\/Remote Control Agent>= 08-00, <= 08-00-04
HitachiJob Management Partner 1\/Remote Control Agent>= 08-10, <= 08-10-05
HitachiJob Management Partner 1\/Remote Control Agent>= 08-51, <= 08-51-18
HitachiJob Management Partner 1\/Remote Control Agent>= 09-00, <= 09-00-07
HitachiJob Management Partner 1\/Remote Control Agent>= 09-50, <= 09-50-09
HitachiJob Management Partner 1\/Remote Control Agent>= 09-51, <= 09-51-15
HitachiJob Management Partner 1\/Software Distribution Client>= 08-00, <= 08-00-05
HitachiJob Management Partner 1\/Software Distribution Client>= 08-10, <= 08-10-06
HitachiJob Management Partner 1\/Software Distribution Client>= 08-51, <= 08-51-19
HitachiJob Management Partner 1\/Software Distribution Client>= 09-00, <= 09-00-09
HitachiJob Management Partner 1\/Software Distribution Client>= 09-50, <= 09-50-09
HitachiJob Management Partner 1\/Software Distribution Client>= 09-51, <= 09-51-13
HitachiJob Management Partner 1\/Software Distribution Manager>= 08-00, <= 08-00-07
HitachiJob Management Partner 1\/Software Distribution Manager>= 08-10, <= 08-10-06
HitachiJob Management Partner 1\/Software Distribution Manager>= 08-51, <= 08-51-19
HitachiJob Management Partner 1\/Software Distribution Manager>= 09-00, <= 09-00-09
HitachiJob Management Partner 1\/Software Distribution Manager>= 09-50, <= 09-50-09
HitachiJob Management Partner 1\/Software Distribution Manager>= 09-51, <= 09-51-13
HitachiJp1\/It Desktop Management-Manager>= 09-50, <= 09-50-03
HitachiJp1\/It Desktop Management-Manager>= 09-51, <= 09-51-05
HitachiJp1\/It Desktop Management-Manager>= 10-00, <= 10-00-02
HitachiJp1\/It Desktop Management-Manager>= 10-01, <= 10-01-05
HitachiJp1\/It Desktop Management-Manager>= 10-02, <= 10-02-05
HitachiJp1\/It Desktop Management-Manager>= 10-10, <= 10-10-16
HitachiJp1\/It Desktop Management 2-Manager>= 10-50, <= 10-50-12
HitachiJp1\/It Desktop Management 2-Manager>= 11-00, <= 11-00-11
HitachiJp1\/It Desktop Management 2-Manager>= 11-01, <= 11-01-12
HitachiJp1\/It Desktop Management 2-Manager>= 11-10, <= 11-10-10
HitachiJp1\/It Desktop Management 2-Manager>= 11-50, <= 11-50-08
HitachiJp1\/It Desktop Management 2-Manager>= 11-51, <= 11-51-10
HitachiJp1\/It Desktop Management 2-Manager>= 12-00, <= 12-00-09
HitachiJp1\/It Desktop Management 2-Manager>= 12-10, <= 12-10-07
HitachiJp1\/It Desktop Management 2-Manager>= 12-50, <= 12-50-03
HitachiJp1\/It Desktop Management 2-Operations Director>= 11-01, <= 11-01-12
HitachiJp1\/It Desktop Management 2-Operations Director>= 11-10, <= 11-10-10
HitachiJp1\/It Desktop Management 2-Operations Director>= 11-50, <= 11-50-08
HitachiJp1\/It Desktop Management 2-Operations Director>= 11-51, <= 11-51-10
HitachiJp1\/It Desktop Management 2-Operations Director>= 12-00, <= 12-00-09
HitachiJp1\/It Desktop Management 2-Operations Director>= 12-10, <= 12-10-07
HitachiJp1\/It Desktop Management 2-Operations Director>= 12-50, <= 12-50-03
HitachiJp1\/Netdm\/Dm Client>= 08-00, <= 08-00-09
HitachiJp1\/Netdm\/Dm Client>= 08-01, <= 08-01-04

Showing 50 of 105 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-29644?
Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the underlying OS.
How severe is CVE-2021-29644?
CVE-2021-29644 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 2.45% probability of exploitation in the next 30 days.
How do I fix CVE-2021-29644?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-29644?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST