Vulnerability Details CVE-2021-26607
An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 75.4%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 10.0
Products affected by CVE-2021-26607
-
cpe:2.3:a:tobesoft:nexacro:14.0.0.0
-
cpe:2.3:a:tobesoft:nexacro:14.0.1.3600
-
cpe:2.3:a:tobesoft:nexacro:17.1.2.500
-
cpe:2.3:a:tobesoft:nexacro:17.1.2.600
-
cpe:2.3:a:tobesoft:nexacro:17.1.3.301
-
cpe:2.3:o:microsoft:windows:-