CVE-2021-40376

otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A remote attack may be possible as well, by leveraging WsHTTPBinding for HTTP traffic on TCP port 9000.
Configurations

Configuration 1

cpe:2.3:a:otris:update_manager:1.2.1.0:*:*:*:*:*:*:*

Information

Published : 2022-03-10 05:43

Updated : 2022-03-16 03:23


NVD link : CVE-2021-40376

Mitre link : CVE-2021-40376

Products Affected
No products.
CWE