Vulnerability Description
EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the location of the "sendmail" application in the "cacti" configuration page (by default/usr/sbin/sendmail) it is possible to execute any command, which will be executed when we make a test of the configuration ("send test mail").
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eyesofnetwork | Eyesofnetwork | < 2021-07-07 |
References
- https://eyesofnetwork.comBroken Link
- https://www.eyesofnetwork.com/en/news/vulnerabilite-cactiPatchVendor Advisory
- https://eyesofnetwork.comBroken Link
- https://www.eyesofnetwork.com/en/news/vulnerabilite-cactiPatchVendor Advisory
FAQ
What is CVE-2021-40643?
CVE-2021-40643 is a vulnerability with a CVSS score of 9.8 (CRITICAL). EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the location of the "sendmail" application in the "cacti" configuration page (by de...
How severe is CVE-2021-40643?
CVE-2021-40643 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-40643?
Check the references section above for vendor advisories and patch information. Affected products include: Eyesofnetwork Eyesofnetwork.