Aller au contenu

Fiche vulnérabilité

CVE-2021-38289 : faille élevée novastar novaicare (CVSS 8.8)

Description

An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts. NOTE: As of April 2026, the vendor has officially decommissioned the affected legacy endpoints and associated services. The vulnerability is mitigated as the functional logic is no longer operational and the URLs have been removed from production.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
12 juil. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • novastar novaicare

Références

Rechercher une autre vulnérabilité dans la base CVE