Lucene search

K
cvelistMitreCVELIST:CVE-2021-42324
HistoryApr 05, 2022 - 1:05 a.m.

CVE-2021-42324

2022-04-0501:05:29
mitre
www.cve.org
1
dcn s4600-10p-si
improper parameter validation
sandbox environment
system commands
root access
shell metacharacters
capture command
physical access

AI Score

7.9

Confidence

High

EPSS

0.001

Percentile

28.0%

An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authenticated attacker to escape the sandbox environment and execute system commands as root via shell metacharacters in the capture command parameters. Command output will be shown on the Serial interface of the device. Exploitation requires both credentials and physical access.

AI Score

7.9

Confidence

High

EPSS

0.001

Percentile

28.0%

Related for CVELIST:CVE-2021-42324