{"api_version":"1","generated_at":"2026-07-23T14:33:23+00:00","cve":"CVE-2021-26622","urls":{"html":"https://cve.report/CVE-2021-26622","api":"https://cve.report/api/cve/CVE-2021-26622.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-26622","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-26622"},"summary":{"title":"CVE-2021-26622","description":"An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability.","state":"PUBLIC","assigner":"vuln@krcert.or.kr","published_at":"2022-03-25 19:15:00","updated_at":"2023-06-26 18:22:00"},"problem_types":["CWE-94"],"metrics":[],"references":[{"url":"https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66580","name":"https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66580","refsource":"MISC","tags":[],"title":"Security Advisory | KrCERT/CC - KISA 인터넷 보호나라&KrCERT","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-26622","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-26622","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"26622","vulnerable":"1","versionEndIncluding":"4.0.145.0831","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"genians","cpe5":"genian_nac","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"26622","vulnerable":"1","versionEndIncluding":"5.0.42.0827","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"genians","cpe5":"genian_nac","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"26622","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"vuln@krcert.or.kr","ID":"CVE-2021-26622","STATE":"PUBLIC","TITLE":"Genian NAC remote code execution vulnerability"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Genian NAC Suite V4.0","version":{"version_data":[{"platform":"Windows","version_affected":"<=","version_value":"4.0.145.0831"}]}}]},"vendor_name":"Genians Co., Ltd"},{"product":{"product_data":[{"product_name":"Genian NAC V5.0 & Genian NAC Suite V5.0","version":{"version_data":[{"platform":"Windows","version_affected":"<=","version_value":"5.0.42.0827 "}]}}]},"vendor_name":"Genians Co., Ltd"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":9.6,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20 Improper Input Validation"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66580","name":"https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66580"}]},"source":{"discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2022-03-25 19:15:00","lastModifiedDate":"2023-06-26 18:22:00","problem_types":["CWE-94"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:genians:genian_nac:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndIncluding":"4.0.145.0831","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:genians:genian_nac:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndIncluding":"5.0.42.0827","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"26622","Ordinal":"201693","Title":"CVE-2021-26622","CVE":"CVE-2021-26622","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"26622","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}