CVE-2021-42372 is a critical shell command injection vulnerability affecting XoruX LPAR2RRD and STOR2RRD versions prior to 7.30. An authenticated remote attacker can exploit this flaw via the HW Events SNMP community to execute arbitrary shell commands as the service user. With a CVSS score of 8.8 (High), this vulnerability allows for complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is currently no public exploit code, nor is it listed on the CISA KEV catalog, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.30CPE matchmatch criteria | cpe:2.3:a:xorux:lpar2rrd:*:*:*:*:*:*:*:* | ||
< 7.30CPE matchmatch criteria | cpe:2.3:a:xorux:stor2rrd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.