CVE-2021-20658: OS Command Injection
Published Feb 24, 2021
·Updated
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors.
Affected Software
2 affected components
Contec Sv-cpt-mc310 Firmware<6.5
Contec Sv-cpt-mc310
Event History
Feb 24, 2021
CVE Published
via MITRE·03:51 AM
Data Sourced
via MITRE·03:51 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20658?
CVE-2021-20658 has a high severity rating due to the potential for arbitrary OS command execution.
2
How do I fix CVE-2021-20658?
To fix CVE-2021-20658, upgrade the Contec SV-CPT-MC310 Firmware to version 6.5 or higher.
3
What systems are affected by CVE-2021-20658?
CVE-2021-20658 affects SolarView Compact SV-CPT-MC310 devices running firmware versions prior to 6.5.
4
What kind of attacks can CVE-2021-20658 facilitate?
CVE-2021-20658 can facilitate remote code execution attacks by allowing attackers to execute arbitrary OS commands.
5
Is there a known workaround for CVE-2021-20658?
There are no known workarounds for CVE-2021-20658; the recommended action is to update the firmware.