← Back to CVE List
Vulnerability Intelligence Report
Unauthenticated remote command execution with SYSTEM privileges in Vembu products

CVE-2021-26472

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using this command argument an unauthenticated attacker can execute arbitrary OS commands with SYSTEM privileges.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:2.46%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
vembu bdr_suite all
vembu offsite_dr all
microsoft windows all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
2.459%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2021-02-01T00:00:00
Published2021-06-08T18:37:29
Patch Date2021-07-07
Last Updated2024-09-16T22:08:25

LINK COPIED TO CLIPBOARD