Remote Code Execution Vulnerability in Genivia gSOAP Plugin
CVE-2021-21783

9.8CRITICAL

Key Information:

Vendor

Genivia

Status
Vendor
CVE Published:
25 March 2021

What is CVE-2021-21783?

A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. When an attacker crafts a specially formatted SOAP request, it could result in remote code execution on the targeted system. This vulnerability can be triggered through the transmission of an HTTP request, allowing potential attackers to execute arbitrary commands, thereby compromising the integrity of affected systems.

Affected Version(s)

Genivia Genivia gSOAP 2.8.109, Genivia gSOAP 2.8.110

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.