Vulnerability Details CVE-2021-30642
An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior to 8.2.1-NSR2 or 8.2.2 allows a remote, unauthenticated attacker to execute arbitrary OS commands on the target with elevated privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 80.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2021-30642
-
cpe:2.3:a:symantec:security_analytics:7.2
-
cpe:2.3:a:symantec:security_analytics:7.2.1
-
cpe:2.3:a:symantec:security_analytics:7.2.2
-
cpe:2.3:a:symantec:security_analytics:7.2.3
-
cpe:2.3:a:symantec:security_analytics:8.1
-
cpe:2.3:a:symantec:security_analytics:8.2