An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior to 8.2.1-NSR2 or 8.2.2 allows a remote, unauthenticated attacker to execute arbitrary OS commands on the target with elevated privileges.
                
            References
                    | Link | Resource | 
|---|---|
| https://support.broadcom.com/security-advisory/content/security-advisories/0/SYMSA17969 | Third Party Advisory | 
| https://support.broadcom.com/security-advisory/content/security-advisories/0/SYMSA17969 | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 06:04
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://support.broadcom.com/security-advisory/content/security-advisories/0/SYMSA17969 - Third Party Advisory | 
Information
                Published : 2021-04-27 15:15
Updated : 2024-11-21 06:04
NVD link : CVE-2021-30642
Mitre link : CVE-2021-30642
CVE.ORG link : CVE-2021-30642
JSON object : View
Products Affected
                symantec
- security_analytics
CWE
                
                    
                        
                        CWE-78
                        
            Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
