← Back

CVE-2021-35217

nvd nist
Published: Sep 8, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and reported to us by ZDI. An Authenticated Attacker could exploit it by executing WSAsyncExecuteTasks deserialization of untrusted data.

Affected (1)

1 product
Patch Manager
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2020.2.5

Timeline

No history available yet.