Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via the getlogs.cgi tcpdump feature. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110 1.1.2.8, Nexto NX5210 1.1.2.8, Nexto Xpress XP300 1.8.11.0, Nexto Xpress XP315 1.8.11.0, Nexto Xpress XP325 1.8.11.0, Nexto Xpress XP340 1.8.11.0, and Hadron Xtorm HX3040 1.7.58.0.
References
Link | Resource |
---|---|
https://seclists.org/fulldisclosure/2021/Aug/21 | Exploit Mailing List Third Party Advisory |
https://www.altus.com.br/ | Vendor Advisory |
https://seclists.org/fulldisclosure/2021/Aug/21 | Exploit Mailing List Third Party Advisory |
https://www.altus.com.br/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
AND |
|
History
21 Nov 2024, 06:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://seclists.org/fulldisclosure/2021/Aug/21 - Exploit, Mailing List, Third Party Advisory | |
References | () https://www.altus.com.br/ - Vendor Advisory |
26 Aug 2021, 19:13
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 9.0
v3 : 8.8 |
References | (MISC) https://www.altus.com.br/ - Vendor Advisory | |
References | (MISC) https://seclists.org/fulldisclosure/2021/Aug/21 - Exploit, Mailing List, Third Party Advisory | |
CWE | CWE-78 | |
CPE | cpe:2.3:h:altus:hadron_xtorm_hx3040:-:*:*:*:*:*:*:* cpe:2.3:o:altus:nexto_nx5101_firmware:1.8.11.0:*:*:*:*:*:*:* cpe:2.3:h:altus:nexto_nx5110:-:*:*:*:*:*:*:* cpe:2.3:h:altus:nexto_nx3003:-:*:*:*:*:*:*:* cpe:2.3:h:altus:nexto_nx3004:-:*:*:*:*:*:*:* cpe:2.3:o:altus:nexto_nx5110_firmware:1.1.2.8:*:*:*:*:*:*:* cpe:2.3:o:altus:nexto_xpress_xp315_firmware:1.8.11.0:*:*:*:*:*:*:* cpe:2.3:h:altus:nexto_nx3030:-:*:*:*:*:*:*:* cpe:2.3:h:altus:nexto_nx5101:-:*:*:*:*:*:*:* cpe:2.3:h:altus:nexto_nx5210:-:*:*:*:*:*:*:* cpe:2.3:o:altus:nexto_nx3004_firmware:1.8.11.0:*:*:*:*:*:*:* cpe:2.3:o:altus:nexto_xpress_xp300_firmware:1.8.11.0:*:*:*:*:*:*:* cpe:2.3:h:altus:nexto_nx3005:-:*:*:*:*:*:*:* cpe:2.3:h:altus:nexto_nx5100:-:*:*:*:*:*:*:* cpe:2.3:h:altus:nexto_nx3020:-:*:*:*:*:*:*:* cpe:2.3:h:altus:nexto_xpress_xp325:-:*:*:*:*:*:*:* cpe:2.3:o:altus:nexto_nx5210_firmware:1.1.2.8:*:*:*:*:*:*:* cpe:2.3:h:altus:nexto_xpress_xp300:-:*:*:*:*:*:*:* cpe:2.3:o:altus:nexto_nx3005_firmware:1.8.11.0:*:*:*:*:*:*:* cpe:2.3:o:altus:nexto_nx3010_firmware:1.8.3.0:*:*:*:*:*:*:* cpe:2.3:h:altus:nexto_nx3010:-:*:*:*:*:*:*:* cpe:2.3:o:altus:nexto_nx3003_firmware:1.8.11.0:*:*:*:*:*:*:* cpe:2.3:o:altus:hadron_xtorm_hx3040_firmware:1.7.58.0:*:*:*:*:*:*:* cpe:2.3:o:altus:nexto_nx3020_firmware:1.8.3.0:*:*:*:*:*:*:* cpe:2.3:o:altus:nexto_nx3030_firmware:1.8.3.0:*:*:*:*:*:*:* cpe:2.3:o:altus:nexto_xpress_xp340_firmware:1.8.11.0:*:*:*:*:*:*:* cpe:2.3:h:altus:nexto_xpress_xp340:-:*:*:*:*:*:*:* cpe:2.3:o:altus:nexto_xpress_xp325_firmware:1.8.11.0:*:*:*:*:*:*:* cpe:2.3:h:altus:nexto_xpress_xp315:-:*:*:*:*:*:*:* cpe:2.3:o:altus:nexto_nx5100_firmware:1.8.11.0:*:*:*:*:*:*:* |
23 Aug 2021, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-08-23 05:15
Updated : 2024-11-21 06:19
NVD link : CVE-2021-39244
Mitre link : CVE-2021-39244
CVE.ORG link : CVE-2021-39244
JSON object : View
Products Affected
altus
- nexto_nx5100
- nexto_xpress_xp300
- nexto_nx3020_firmware
- nexto_xpress_xp300_firmware
- nexto_xpress_xp325
- hadron_xtorm_hx3040_firmware
- nexto_nx5100_firmware
- nexto_nx5110_firmware
- nexto_nx3004
- nexto_nx3010
- nexto_xpress_xp340_firmware
- nexto_nx3020
- nexto_xpress_xp340
- nexto_nx3005
- nexto_nx3003
- nexto_nx3003_firmware
- nexto_nx3030_firmware
- nexto_xpress_xp325_firmware
- nexto_nx5101
- nexto_nx3030
- hadron_xtorm_hx3040
- nexto_nx3010_firmware
- nexto_xpress_xp315
- nexto_nx3005_firmware
- nexto_nx5210_firmware
- nexto_nx5210
- nexto_nx5110
- nexto_nx3004_firmware
- nexto_xpress_xp315_firmware
- nexto_nx5101_firmware
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')