Aller au contenu

Fiche vulnérabilité

CVE-2021-36667 : faille élevée druva insync client (CVSS 7.8)

Description

Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
12 juil. 2022
Dernière mise à jour
9 juil. 2026

Produits concernés

  • druva insync client

Références

Rechercher une autre vulnérabilité dans la base CVE