HIGH · 8.1

CVE-2021-29644

Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this iss...

Vulnerability Description

Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the underlying OS.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HitachiIt Operations Director>= 02-50, <= 02-50-07
HitachiJob Management Partner 1\/It Desktop Management-Manager>= 09-50, <= 09-50-03
HitachiJob Management Partner 1\/It Desktop Management 2-Manager>= 10-50, <= 10-50-11
HitachiJob Management Partner 1\/Remote Control Agent>= 08-00, <= 08-00-04
HitachiJob Management Partner 1\/Software Distribution Client>= 08-00, <= 08-00-05
HitachiJob Management Partner 1\/Software Distribution Manager>= 08-00, <= 08-00-07
HitachiJp1\/It Desktop Management-Manager>= 09-50, <= 09-50-03
HitachiJp1\/It Desktop Management 2-Manager>= 10-50, <= 10-50-12
HitachiJp1\/It Desktop Management 2-Operations Director>= 11-01, <= 11-01-12
HitachiJp1\/Netdm\/Dm Client>= 08-00, <= 08-00-09
HitachiJp1\/Netdm\/Dm Client-Remote Control Feature>= 08-00, <= 08-00-06
HitachiJp1\/Netdm\/Dm Manager>= 08-00, <= 08-00-09
HitachiJp1\/Netm\/Remote Control Agent>= 08-00, <= 08-00-06
HitachiJp1\/Remote Control Agent>= 11-00, <= 11-00-02
MicrosoftWindows-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-29644?

CVE-2021-29644 is a vulnerability with a CVSS score of 8.1 (HIGH). Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this iss...

How severe is CVE-2021-29644?

CVE-2021-29644 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-29644?

Check the references section above for vendor advisories and patch information. Affected products include: Hitachi It Operations Director, Hitachi Job Management Partner 1\/It Desktop Management-Manager, Hitachi Job Management Partner 1\/It Desktop Management 2-Manager, Hitachi Job Management Partner 1\/Remote Control Agent, Hitachi Job Management Partner 1\/Software Distribution Client.