« Volver al listado

CVE-2021-20706

Estado: ModificadaAlta (7.5)—

Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-20706",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt-info@cyber.jp.nec.com",
      "affectedData": [
        {
          "vendor": "NEC Corporation",
          "product": "CLUSTERPRO X",
          "versions": [
            {
              "status": "affected",
              "version": "CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-11-03T00:15:07.930",
  "references": [
    {
      "url": "https://jpn.nec.com/security-info/secinfo/nv21-015_en.html",
      "source": "psirt-info@cyber.jp.nec.com"
    },
    {
      "url": "https://jpn.nec.com/security-info/secinfo/nv21-015_en.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de validación de entrada inadecuada en el WebManager CLUSTERPRO X 4.3 para Windows y anteriores, EXPRESSCLUSTER X 4.3 para Windows y anteriores, CLUSTERPRO X 4.3 SingleServerSafe para Windows y anteriores, EXPRESSCLUSTER X 4.3 SingleServerSafe para Windows y anteriores permite a un atacante la carga remota de archivos a través de la red"
    }
  ],
  "lastModified": "2026-06-17T03:34:17.553",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nec:clusterpro_x:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "109DED36-3D51-4EDF-8187-63F3415BC2B7",
              "versionEndIncluding": "4.3",
              "versionStartIncluding": "1.0"
            },
            {
              "criteria": "cpe:2.3:a:nec:clusterpro_x_singleserversafe:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AADFE051-D950-4027-B9C4-EB53B3881001",
              "versionEndIncluding": "4.3",
              "versionStartIncluding": "1.0"
            },
            {
              "criteria": "cpe:2.3:a:nec:expresscluster_x:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EBD9B299-1A5E-4329-BC51-606A0EF00822",
              "versionEndIncluding": "4.3",
              "versionStartIncluding": "1.0"
            },
            {
              "criteria": "cpe:2.3:a:nec:expresscluster_x_singleserversafe:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5717B4C8-9622-4A08-9E29-E6B66800CE99",
              "versionEndIncluding": "4.3",
              "versionStartIncluding": "1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt-info@cyber.jp.nec.com"
}