CVE-2021-26724: Authenticated command injection when changing date settings or hostname in Guardian/CMC before 20.0.7.4
OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this OS Command Injection vulnerability?
The vulnerability ID for this OS Command Injection vulnerability is CVE-2021-26724.
What is the severity level of CVE-2021-26724?
CVE-2021-26724 has a severity level of critical.
Which software versions are affected by CVE-2021-26724?
CVE-2021-26724 affects Nozomi Networks Guardian 20.0.7.3 and prior versions.
How can an authenticated administrator exploit CVE-2021-26724?
An authenticated administrator can exploit CVE-2021-26724 by changing date settings or hostname using the web GUI of Nozomi Networks Guardian and CMC, allowing for remote code execution.
Where can I find more information about CVE-2021-26724?
You can find more information about CVE-2021-26724 at the following reference link: https://security.nozominetworks.com/NN-2021:1-01