First published: Tue Nov 02 2021(Updated: )
Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Nec Clusterpro X | >=1.0<=4.3 | |
Nec Clusterpro X Singleserversafe | >=1.0<=4.3 | |
Nec Expresscluster X | >=1.0<=4.3 | |
Nec Expresscluster X Singleserversafe | >=1.0<=4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20700 is a buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, and EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier.
The severity of CVE-2021-20700 is critical, with a severity value of 9.8.
An attacker can exploit CVE-2021-20700 to achieve remote code execution.
CVE-2021-20700 affects the NEC Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, and EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier.
To fix CVE-2021-20700, it is recommended to update to a version that is not affected by the vulnerability. Refer to the vendor's security advisory for more information.