jvn.jp
https://jvn.jp/en/jp/JVN58774946/index.html CVE-2021-20655
HIGHRansomware
soliton filezen Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2021-20655 has a selected CVSS score of 7.2 (high). VulnCheck reports CVE-2021-20655 use in known ransomware campaigns.
Description
FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 22, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · VulnCheck
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2 | affected | |
filezenBrowse soliton / filezen | VulnCheck | Version data not supplied | |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-20655 soliton.co.jp
https://www.soliton.co.jp/support/2021/004334.html