CVE-2021-40222
HIGH 9.0EPSS 4.7%
Rittal CMC PU III Web management Version affected: V3.11.00_2. Version fixed: V3.17.10 is affected by a remote code execution vulnerablity. It is possible to introduce shell code to create a reverse shell in the PU-Hostname field of the TCP/IP Configuration dialog. Web application fails to sanitize user input on Network TCP/IP configuration page. This allows the attacker to inject commands as root on the device which will be executed once the data is received.
- CVSS v3.1
- 7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 4.69% chance of exploitation in the next 30 days, 91th percentile
- Published
- 2021-09-09
- Updated
- 2024-08-04
Proof-of-concept exploits (2)
- asang17/CVE-2021-RCE0★ · 2021-09-13
- asang17/CVE-2021-402220★ · 2021-09-13