Description
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.
Scores
CVSS v3
8.8
EPSS
0.0007
EPSS Percentile
21.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-294
Status
published
Products (24)
nec/expresscluster_x
1.0 (2 CPE variants)
nec/expresscluster_x
2.0 (2 CPE variants)
nec/expresscluster_x
2.1 (2 CPE variants)
nec/expresscluster_x
3.0 (2 CPE variants)
nec/expresscluster_x
3.1 (2 CPE variants)
nec/expresscluster_x
3.2 (2 CPE variants)
nec/expresscluster_x
3.3 (2 CPE variants)
nec/expresscluster_x
4.0 (2 CPE variants)
nec/expresscluster_x
4.1 (2 CPE variants)
nec/expresscluster_x
4.2 (2 CPE variants)
... and 14 more
Published
Nov 17, 2023
Tracked Since
Feb 18, 2026