CVE-2021-40612: Critical severity opmantek open-audit vulnerability
Published Dec 22, 2021
·Updated
An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in codeigniter/application/controllers/util.php allows an attacker perform command execution without echoes.
Affected Software
1 affected component
Opmantek Open-AudIT>=3.5.0<4.3.0
Remediation
Event History
Dec 22, 2021
CVE Published
via MITRE·12:12 PM
Data Sourced
via MITRE·12:12 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-40612.
2
What is the severity of CVE-2021-40612?
The severity of CVE-2021-40612 is critical with a CVSS score of 9.8.
3
What is the affected software?
The affected software is Opmantek Open-AudIT versions 3.5.0 to 4.3.0.
4
How does CVE-2021-40612 allow an attacker to perform command execution?
CVE-2021-40612 allows an attacker to perform command execution without authentication by exploiting a vulnerability in code_igniter/application/controllers/util.php.
5
How can I fix CVE-2021-40612?
To fix CVE-2021-40612, you should update to the latest version of Opmantek Open-AudIT.