CVE-2021-40376

otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A remote attack may be possible as well, by leveraging WsHTTPBinding for HTTP traffic on TCP port 9000.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:otris:update_manager:1.2.1.0:*:*:*:*:*:*:*

Information

Published : 2022-03-10 09:43

Updated : 2022-03-15 20:23


NVD link : CVE-2021-40376

Mitre link : CVE-2021-40376


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

otris

  • update_manager