First published: Wed Dec 08 2021(Updated: )
A privilege escalation vulnerability exists in the Remote Server functionality of Dream Report ODS Remote Connector 20.2.16900.0. A specially-crafted command injection can lead to elevated capabilities. An attacker can provide a malicious file to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dreamreport Remote Connector | =20.2.16900.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21957 is classified as a privilege escalation vulnerability.
CVE-2021-21957 allows an attacker to execute a specially crafted command that can escalate privileges.
CVE-2021-21957 affects Dream Report ODS Remote Connector version 20.2.16900.0.
To remediate CVE-2021-21957, update Dream Report ODS Remote Connector to the latest patched version.
Yes, CVE-2021-21957 can be exploited remotely through the Remote Server functionality.