SecBoard
Zurück zur CVE-Übersicht

CVE-2021-42237

CRITICAL(9.8)KEV — Aktiv ausgenutzt

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Risk Signal Score84/100 — KRITISCH
  • CVSS 9.8 — Kritisch
  • EPSS 98% — sehr wahrscheinlich ausgenutzt
  • Im CISA KEV-Katalog (aktiv ausgenutzt)

CISA KEV

Bestätigt ausgenutzt

EPSS-Score

97.9%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

9.8

Technische Schwere

SecBoard-Einordnung

CVE-2021-42237 betrifft Sitecore XP Versionen von 7.5 Initial Release bis 8.2 Update-7 und ermöglicht eine unsichere Deserialisierung. Diese Schwachstelle kann zu () auf dem betroffenen System führen. Für die Ausnutzung sind weder Authentifizierung noch spezielle Konfigurationen erforderlich.

KI-gestützte Einordnung auf Basis der NVD-Daten.

Beschreibung

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.

Referenzen