CVE-2021-42324 affects DCN S4600-10P-SI devices before R0241.0470, allowing a low-privileged, authenticated attacker to escape the console sandbox and execute root-level system commands. This high-severity vulnerability (CVSS 7.4) requires both physical access and valid credentials, leveraging improper parameter validation with shell metacharacters in the capture command. While the potential impact is significant, there is no evidence of active exploitation, public exploit code, or community discussion, suggesting a low immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= r0241.0370, < r0241.0470CPE matchmatch criteria | cpe:2.3:o:dcnglobal:s4600-10p-si_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.