CVE-2021-33527
Last modified
CVE-2021-33527 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In MB connect line mbDIALUP versions <= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORITY\SYSTEM that will not correctly validate the input. This can lead to an arbitrary code execution with the privileges of the service.. EPSS estimates a 4.52% chance of exploitation in the next 30 days.
Description
In MB connect line mbDIALUP versions <= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORITY\SYSTEM that will not correctly validate the input. This can lead to an arbitrary code execution with the privileges of the service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mbconnectline | Mbdialup | <= 3.9r0.0 |
References
- https://cert.vde.com/de-de/advisories/vde-2021-017Third Party Advisory
- https://cert.vde.com/de-de/advisories/vde-2021-017Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33527?
How severe is CVE-2021-33527?
How do I fix CVE-2021-33527?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-33515The submission service in Dovecot before 2.3.15 allows START…4.8
- CVE-2021-33516An issue was discovered in GUPnP before 1.0.7 and 1.1.x and …8.1
- CVE-2021-3352The Software Development Kit in Mitel MiContact Center Busin…9.1
- CVE-2021-33523MashZone NextGen through 10.7 GA allows a remote authenticat…7.2
- CVE-2021-33525EyesOfNetwork eonweb through 5.3-11 allows Remote Command Ex…8.8
- CVE-2021-33526In MB connect line mbDIALUP versions <= 3.9R0.0 a low privil…7.8
- CVE-2021-33528In Weidmueller Industrial WLAN devices in multiple versions …8.8
- CVE-2021-33529In Weidmueller Industrial WLAN devices in multiple versions …7.5
- CVE-2021-33530In Weidmueller Industrial WLAN devices in multiple versions …8.8
- CVE-2021-33531In Weidmueller Industrial WLAN devices in multiple versions …8.8
- CVE-2021-33532In Weidmueller Industrial WLAN devices in multiple versions …8.8
- CVE-2021-33533In Weidmueller Industrial WLAN devices in multiple versions …8.8
Are you affected by CVE-2021-33527?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
