CVE-2021-27285

HIGH

Inspur ClusterEngine <4.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execute arbitrary commands via /opt/tsce4/torque6/bin/getJobsByShell.

Exploits (1)

nomisec WORKING POC
by fjh1997 · poc
https://github.com/fjh1997/CVE-2021-27285

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://github.com/fjh1997/CVE-2021-27285

Scores

CVSS v3 8.4
EPSS 0.0015
EPSS Percentile 35.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (1)
inspur/clusterengine 4.0
Published Jan 06, 2025
Tracked Since Feb 18, 2026