CVE-2021-21315 — System Information Library for Node.JS Command Injection
CVE-2021-21315: System Information Library for Node.JS Command Injection
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Npm package |
| Product | System Information Library for Node.JS |
| Date added | 2022-01-18 |
| Due date | 2022-02-01 |
| Ransomware campaign use | Unknown |
Description
In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.
Required action (CISA)
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2021-21315
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-21315
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog