Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability.

CVSS 1 Total

ScoreSeverityVersionVector String
9.6CRITICAL3.1CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Product Status

Learn more

Versions 1 Total

Default Status: unknown

affected

Versions 1 Total

Default Status: unknown

affected

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.