CVE-2021-40376: High severity otris update manager vulnerability
otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A remote attack may be possible as well, by leveraging WsHTTPBinding for HTTP traffic on TCP port 9000.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-40376?
CVE-2021-40376 is classified as a high severity vulnerability due to potential local privilege escalation to SYSTEM access.
How do I fix CVE-2021-40376?
To fix CVE-2021-40376, you should update the otris Update Manager to version 1.2.1.1 or later.
What are the attack vectors for CVE-2021-40376?
CVE-2021-40376 can be exploited through local access or potentially via remote attacks leveraging WsHTTPBinding over HTTP traffic on TCP port 9000.
Who is affected by CVE-2021-40376?
Any users operating otris Update Manager version 1.2.1.0 are affected by CVE-2021-40376.
What does CVE-2021-40376 exploit?
CVE-2021-40376 exploits unauthenticated calls to exposed interfaces over a .NET named pipe.