CVE-2021-21388Improper Input Validation in Systeminformation

Severity
9.8CRITICALNVD
CNA8.9
EPSS
0.6%
top 30.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 29

Description

systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions of systeminformation prior to 5.6.4. The issue has been fixed with a parameter check on user input. Please upgrade to version >= 5.6.4. If you cannot upgrade, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() and other commands. Only allow strings, reject any arra

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

Patches

🔴Vulnerability Details

3
CVEList
Command Injection Vulnerability in systeminformation2021-04-29
GHSA
Command Injection Vulnerability in systeminformation2021-04-06
OSV
Command Injection Vulnerability in systeminformation2021-04-06
CVE-2021-21388 — Improper Input Validation | cvebase