CVE-2021-38289

An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts. NOTE: As of April 2026, the vendor has officially decommissioned the affected legacy endpoints and associated services. The vulnerability is mitigated as the functional logic is no longer operational and the URLs have been removed from production.
Configurations

Configuration 1 (hide)

cpe:2.3:a:novastar:novaicare:7.16.0:*:*:*:*:*:*:*

History

07 Apr 2026, 17:16

Type Values Removed Values Added
References
  • () https://security.novaicare.com/advisory-cve-2021-38289.html -
Summary (en) An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts. (en) An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts. NOTE: As of April 2026, the vendor has officially decommissioned the affected legacy endpoints and associated services. The vulnerability is mitigated as the functional logic is no longer operational and the URLs have been removed from production.

21 Nov 2024, 06:16

Type Values Removed Values Added
References () https://github.com/viperbluff/Novastar-VNNOX-iCare-Privilege-Escalation - Exploit, Third Party Advisory () https://github.com/viperbluff/Novastar-VNNOX-iCare-Privilege-Escalation - Exploit, Third Party Advisory
References () https://twitter.com/viperbluff/status/1439941380244230150?s=20&t=iPSn8eNxaxUKis5OKSQJRQ - Exploit, Third Party Advisory () https://twitter.com/viperbluff/status/1439941380244230150?s=20&t=iPSn8eNxaxUKis5OKSQJRQ - Exploit, Third Party Advisory

Information

Published : 2022-07-12 14:15

Updated : 2026-04-07 17:16


NVD link : CVE-2021-38289

Mitre link : CVE-2021-38289

CVE.ORG link : CVE-2021-38289


JSON object : View

Products Affected

novastar

  • novaicare
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource