CVE-2021-3029 is an OS Command Injection vulnerability affecting EVOLUCARE ECSIMAGING (aka ECS Imaging) through version 6.21.5. This flaw allows an unauthenticated attacker to achieve root access by injecting shell metacharacters and manipulating IFS via the "file" parameter on the /showfile.php webpage. Rated Critical with a CVSS score of 9.8, it presents a low-complexity attack vector with high impact on confidentiality, integrity, and availability. While no active exploitation or public exploit code is reported, and community discussion is minimal, this vulnerability poses a significant risk to unsupported systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.21.5CPE matchmatch criteria | cpe:2.3:a:evolucare:ecs_imaging:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.