CVE-2021-38120

MEDIUM

NetIQ Advance Auth <6.3.5.1 - Command Injection

Title source: llm
STIX 2.1

Description

A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1.

Scores

CVSS v3 5.1
EPSS 0.0011
EPSS Percentile 28.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-77
Status published
Products (2)
microfocus/netiq_advanced_authentication 6.3 (7 CPE variants)
microfocus/netiq_advanced_authentication < 6.3
Published Aug 28, 2024
Tracked Since Feb 18, 2026