Required CVE Record Information
Description
An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
9.6 | CRITICAL | 3.1 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Product Status
Learn moreVersions 1 Total
Default Status: unknown
affected
Versions 1 Total
Default Status: unknown
affected
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.