CVE-2021-41316
High
Published: 17 September 2021
Published
17 September 2021
Modified
21 November 2024
KEV Added
—
Patch
—
CVSS Score v3.1
8.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS Score
0.0065
71.4th percentile
Risk Priority
17
60% EPSS · 20% KEV · 20% CVSS
Summary
CVE-2021-41316 is a high-severity Argument Injection (CWE-88) vulnerability in Device42 Device42. Its CVSS base score is 8.1 (High).
Operationally, ranked in the top 28.6% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2021-28345
Vulnerability details
The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility. An attacker (with permissions to add or edit jobs run by this utility) can inject an extra argument to overwrite arbitrary files as the…
more
root user on the Remote Collector.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
device42
device42
≤ 17.05.01
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.