CVE-2021-41315 describes a critical OS command injection vulnerability in Device42 Remote Collector versions prior to 17.05.01, specifically within its SNMP Connectivity utility. This flaw allows an authenticated attacker with console access to execute arbitrary operating system commands and escalate privileges, earning a CVSS score of 8.8 (High). While no public exploits, Metasploit modules, or KEV entries exist, and community discussion is minimal, the high CVSS score and direct impact on system integrity warrant attention for affected organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.05.01CPE matchmatch criteria | cpe:2.3:a:device42:remote_collector:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.