CVE-2021-38611
Summary
| CVE | CVE-2021-38611 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-24 12:15:00 UTC |
| Updated | 2021-08-31 11:30:00 UTC |
| Description | A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to execute arbitrary commands, as root, via shell metacharacters in the filename parameter to assets/index.php. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nascent | Remkon Device Manager | 4.0.0.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Nascent RemKon Multiple CVEs | Black Lantern Security | MISC | www.blacklanternsecurity.com | |
| NASCENT Technology Releases RemKon 3.1 to Enhance Audio Experience | MISC | www.nascent.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.