← Back

CVE-2021-32957

nvd nist
Published: Apr 1, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the executable and is therefore vulnerable to binary hijacking.

Affected (4)

2 products
Autosave
Autosave For System Platform
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Auvesy Mdt
Before 6.02.06
From 7.00 to 7.04
Auvesy Mdt
Before 4.01
Version 5.00

References (2)

Source: ics-cert@hq.dhs.gov
MitigationThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government Resource

Timeline

No history available yet.