Privilege Escalation Vulnerability in Inspur ClusterEngine
CVE-2021-27285

8.4HIGH

Key Information:

Vendor

Inspur

Vendor
CVE Published:
6 January 2025

What is CVE-2021-27285?

A security flaw in Inspur ClusterEngine v4.0 enables attackers to escalate local privileges and execute arbitrary commands. This vulnerability arises from improper handling in the /opt/tsce4/torque6/bin/getJobsByShell function, potentially allowing unauthorized command execution by malicious actors. It is essential for users to assess their systems and take appropriate security measures to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.