Vulnerability Description
otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A remote attack may be possible as well, by leveraging WsHTTPBinding for HTTP traffic on TCP port 9000.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Otris | Update Manager | 1.2.1.0 |
Related Weaknesses (CWE)
References
- https://www.otris.comVendor Advisory
- https://www.tuv.com/content-media-files/master-content/global-landingpages/imageExploitThird Party Advisory
- https://www.tuv.com/landingpage/en/vulnerability-disclosure/Third Party Advisory
- https://www.otris.comVendor Advisory
- https://www.tuv.com/content-media-files/master-content/global-landingpages/imageExploitThird Party Advisory
- https://www.tuv.com/landingpage/en/vulnerability-disclosure/Third Party Advisory
FAQ
What is CVE-2021-40376?
CVE-2021-40376 is a vulnerability with a CVSS score of 7.8 (HIGH). otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A remote attack may be possible as well, by leveraging ...
How severe is CVE-2021-40376?
CVE-2021-40376 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40376?
Check the references section above for vendor advisories and patch information. Affected products include: Otris Update Manager.