6.5
CVSSv2

CVE-2021-35049

Published: 25/06/2021 Updated: 12/08/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response in an authenticated session. The vulnerability is present in Fidelis Network and Deception versions before 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fidelissecurity network

fidelissecurity deception

fidelissecurity deception 9.4

fidelissecurity network 9.4