CVE-2021-42324
7.4
Vector
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 0.7 / Impact: 6.0
Source: NVD
Description
An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authenticated attacker to escape the sandbox environment and execute system commands as root via shell metacharacters in the capture command parameters. Command output will be shown on the Serial interface of the device. Exploitation requires both credentials and physical access.
Affected (1)
Products: Dcnglobal: S4600 10p Si Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From r0241.0370 to r0241.0470 |
| Running on/with | Platform Versions |
|---|---|
Dcnglobal S4600 10p Si | All versions |
References (4)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Timeline
No history available yet.