Vulnerability Description
A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the default.aspx User ID field. Arbitrary system commands can be executed through the use of xp_cmdshell.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cerner | Mobile Care | 5.0.0 |
Related Weaknesses (CWE)
References
- https://www.blacklanternsecurity.com/2021-08-13-Cerner-MobileCare-CVE/Third Party Advisory
- https://www.blacklanternsecurity.com/blog/Third Party Advisory
- https://www.cerner.com/solutions/mobilityProductVendor Advisory
- https://www.blacklanternsecurity.com/2021-08-13-Cerner-MobileCare-CVE/Third Party Advisory
- https://www.blacklanternsecurity.com/blog/Third Party Advisory
- https://www.cerner.com/solutions/mobilityProductVendor Advisory
FAQ
What is CVE-2021-36385?
CVE-2021-36385 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the default.aspx User ID ...
How severe is CVE-2021-36385?
CVE-2021-36385 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-36385?
Check the references section above for vendor advisories and patch information. Affected products include: Cerner Mobile Care.