HIGH · 7.4

CVE-2021-42324

An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authe...

Vulnerability Description

An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authenticated attacker to escape the sandbox environment and execute system commands as root via shell metacharacters in the capture command parameters. Command output will be shown on the Serial interface of the device. Exploitation requires both credentials and physical access.

CVSS Score

7.4

HIGH

CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DcnglobalS4600-10P-Si Firmware>= r0241.0370, < r0241.0470
DcnglobalS4600-10P-Si-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-42324?

CVE-2021-42324 is a vulnerability with a CVSS score of 7.4 (HIGH). An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authe...

How severe is CVE-2021-42324?

CVE-2021-42324 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-42324?

Check the references section above for vendor advisories and patch information. Affected products include: Dcnglobal S4600-10P-Si Firmware, Dcnglobal S4600-10P-Si.