CVE-2021-26915
HIGHNetmotionsoftware Netmotion Mobility - Insecure Deserialization
Title source: ruleDescription
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet.
References (3)
Scores
CVSS v3
8.1
EPSS
0.3416
EPSS Percentile
96.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
netmotionsoftware/netmotion_mobility
< 11.73
Timeline
Published
Feb 08, 2021
Tracked Since
Feb 18, 2026