CVE-2021-26622: Genian NAC remote code execution vulnerability
An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26622?
CVE-2021-26622 is classified as a critical vulnerability due to its potential for remote code execution with SYSTEM privileges.
How do I fix CVE-2021-26622?
To mitigate CVE-2021-26622, apply the latest security patches provided by Genian for affected versions of Genian NAC.
What software versions are affected by CVE-2021-26622?
CVE-2021-26622 affects Genian NAC versions from 4.0 to 4.0.145.0831 and from 5.0 to 5.0.42.0827.
Can CVE-2021-26622 affect other systems besides Genian NAC?
No, CVE-2021-26622 specifically targets Genian NAC and is not applicable to other systems.
What type of attack can be executed using CVE-2021-26622?
CVE-2021-26622 allows remote attackers to execute arbitrary malicious code on connected nodes.