6.5
CVSSv2

CVE-2021-27201

Published: 15/02/2021 Updated: 12/07/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a backup comment.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

endian firewall community 3.3.2

Github Repositories

endian_firewall_authenticated_rce CVE-2021-27201 Endinan Firewall Community version 332 authenticated remote code execution as nobody when i was start create backup, output of ps command is be interesting and checking the input is validated ? no we can run commandcheck the permission we can run command as nobody 1-) login in web application 2-) create backup and sel