« Volver al listado

CVE-2021-20707

Estado: ModificadaAlta (7.5)—

Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to read files upload via network..

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-20707",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt-info@cyber.jp.nec.com",
      "affectedData": [
        {
          "vendor": "NEC Corporation",
          "product": "CLUSTERPRO X",
          "versions": [
            {
              "status": "affected",
              "version": "CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-11-03T00:15:07.970",
  "references": [
    {
      "url": "https://jpn.nec.com/security-info/secinfo/nv21-015_en.html",
      "source": "psirt-info@cyber.jp.nec.com"
    },
    {
      "url": "https://jpn.nec.com/security-info/secinfo/nv21-015_en.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to read files upload via network.."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de validación de entrada inadecuada en el Servidor de Transacciones CLUSTERPRO X 4.3 para Windows y anteriores, EXPRESSCLUSTER X 4.3 para Windows y anteriores, CLUSTERPRO X 4.3 SingleServerSafe para Windows y anteriores, EXPRESSCLUSTER X 4.3 SingleServerSafe para Windows y anteriores permite a un atacante leer archivos cargados a través de la red"
    }
  ],
  "lastModified": "2026-06-17T03:34:17.650",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nec:clusterpro_x:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "109DED36-3D51-4EDF-8187-63F3415BC2B7",
              "versionEndIncluding": "4.3",
              "versionStartIncluding": "1.0"
            },
            {
              "criteria": "cpe:2.3:a:nec:clusterpro_x_singleserversafe:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AADFE051-D950-4027-B9C4-EB53B3881001",
              "versionEndIncluding": "4.3",
              "versionStartIncluding": "1.0"
            },
            {
              "criteria": "cpe:2.3:a:nec:expresscluster_x:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EBD9B299-1A5E-4329-BC51-606A0EF00822",
              "versionEndIncluding": "4.3",
              "versionStartIncluding": "1.0"
            },
            {
              "criteria": "cpe:2.3:a:nec:expresscluster_x_singleserversafe:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5717B4C8-9622-4A08-9E29-E6B66800CE99",
              "versionEndIncluding": "4.3",
              "versionStartIncluding": "1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt-info@cyber.jp.nec.com"
}