CVE-2021-42855
10.03.2022, 17:44
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that contains a list of IDs and pre-configured commands. The config file is subsequently used by the "/api/appInternals/1.0/agent/configuration" API to map the corresponding ID to a command to be executed.Enginsight
Vendor | Product | Version |
---|---|---|
riverbed | steelcentral_appinternals_dynamic_sampling_agent | 11.0.0 ≤ 𝑥 < 11.8.8 |
riverbed | steelcentral_appinternals_dynamic_sampling_agent | 12.0.0 ≤ 𝑥 < 12.13.0 |
riverbed | steelcentral_appinternals_dynamic_sampling_agent | 10.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-284 - Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CWE-732 - Incorrect Permission Assignment for Critical ResourceThe product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
References