CVE-2021-34546
Last modified
CVE-2021-34546 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre-logon profile switch button within the Windows logon screen enabled, is able to drop to an administrative shell and execute arbitrary commands as SYSTEM via the "save log to file" feature. To accomplish this, the attacker can navigate to cmd.exe.. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre-logon profile switch button within the Windows logon screen enabled, is able to drop to an administrative shell and execute arbitrary commands as SYSTEM via the "save log to file" feature. To accomplish this, the attacker can navigate to cmd.exe.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netsetman | Netsetman | < 5.0 |
References
- http://packetstormsecurity.com/files/163097/NetSetManPro-4.7.2-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Jun/17Exploit, Mailing List, Third Party Advisory
- https://www.netsetman.comVendor Advisory
- https://www.secuvera.deThird Party Advisory
- https://www.secuvera.de/advisories/secuvera-SA-2021-01.txtExploit, Third Party Advisory
- http://packetstormsecurity.com/files/163097/NetSetManPro-4.7.2-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Jun/17Exploit, Mailing List, Third Party Advisory
- https://www.netsetman.comVendor Advisory
- https://www.secuvera.deThird Party Advisory
- https://www.secuvera.de/advisories/secuvera-SA-2021-01.txtExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-34546?
How severe is CVE-2021-34546?
How do I fix CVE-2021-34546?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-34538Apache Hive before 3.1.3 "CREATE" and "DROP" function operat…7.5
- CVE-2021-34539An issue was discovered in CubeCoders AMP before 2.1.1.8. A …7.2
- CVE-2021-3454Truncated L2CAP K-frame causes assertion failure. Zephyr ver…7.5
- CVE-2021-34540Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the usern…6.1
- CVE-2021-34543The web administration server in Solar-Log 500 before 2.8.2 …7.5
- CVE-2021-34544An issue was discovered in Solar-Log 500 before 2.8.2 Build …6.5
- CVE-2021-34547PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF …4.3
- CVE-2021-34548An issue was discovered in Tor before 0.4.6.5, aka TROVE-202…7.5
- CVE-2021-34549An issue was discovered in Tor before 0.4.6.5, aka TROVE-202…7.5
- CVE-2021-3455Disconnecting L2CAP channel right after invalid ATT request …7.5
- CVE-2021-34550An issue was discovered in Tor before 0.4.6.5, aka TROVE-202…7.5
- CVE-2021-34551PHPMailer before 6.5.0 on Windows allows remote code executi…8.1
Are you affected by CVE-2021-34546?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
