CVE-2021-41569 is a Local File Inclusion (LFI) vulnerability impacting SAS/Intrnet 9.4 build 1520 and earlier versions. This flaw allows unauthenticated attackers to leverage user-controlled macro variables within the default samples library to escape context and retrieve arbitrary files from the host operating system. Rated with a CVSS score of 7.5 (High) and an EPSS score indicating a high likelihood of exploitation, it poses a significant risk to confidentiality. Although not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, it is marked as "Hot List: Active," suggesting current relevance, and a high-severity Nuclei template exists for detection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.4CPE matchmatch criteria | cpe:2.3:a:sas:sas\/intrnet:*:*:*:*:*:*:*:* | ||
9.4CPE matchmatch criteria | cpe:2.3:a:sas:sas\/intrnet:9.4:-:*:*:*:*:*:* | ||
9.4CPE matchmatch criteria | cpe:2.3:a:sas:sas\/intrnet:9.4:build1520:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.