cbcvebase.
CVE-2021-22795
published 2022-04-13

CVE-2021-22795: A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution…

PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.08%
86.2th percentile
A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)

Affected

2 ranges
VendorProductVersion rangeFixed in
schneider-electricstruxureware_data_center_expert<= 7.8.1
schneider_electricstruxureware_data_center_expert>= unspecified < V7.8.1V7.8.1

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is OS Command Injection (CWE-78) in StruxureWare Data Center Expert versions 7.8.1 and prior, exploitable remotely over the network with high privileges — monitor for anomalous OS command execution originating from the DCE application process
  • Attack vector is network-based with low attack complexity and high privilege requirement (AV:N/AC:L/PR:H) — alert on unexpected privileged remote sessions or API calls to StruxureWare Data Center Expert that spawn child processes
  • No known public exploits exist at time of advisory — prioritize detection of novel/custom exploitation attempts against StruxureWare DCE V7.8.1 and prior
  • ·Affected versions are StruxureWare Data Center Expert V7.8.1 and prior; no fixed version was released at time of advisory — verify patch status before assuming remediation
  • ·A companion path traversal vulnerability (CVE-2021-22794, CWE-22) exists in the same product and versions with the same CVSS score — both should be assessed together as they may be chained for exploitation

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.