CVE-2021-34546 describes a vulnerability in NetSetMan Pro versions prior to 5.0, where an unauthenticated attacker with physical access can gain an administrative shell and execute arbitrary commands as SYSTEM. This is achieved by exploiting the "save log to file" feature accessible via the pre-logon profile switch button on the Windows logon screen. The vulnerability has a CVSS score of 6.8 (Medium), indicating high impact on confidentiality, integrity, and availability with low attack complexity, but requires physical access. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0CPE matchmatch criteria | cpe:2.3:a:netsetman:netsetman:*:*:*:*:pro:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.